Cybersecurity experts have revealed a "persistent supply chain attack" on QuickFox, an overseas-focused virtual private network and network acceleration tool This article explores js legitimate firebase. . Fortinet's FortiGuard Labs identifies the ongoing exploit involving a trojanized version of the application to deliver FDMTP, a backdoor utilized by a Chinese state-sponsored threat actor known as Mustang Panda.

The earliest affected version is 3.0.51.0. The campaign targets only Windows users. Malicious code in the installer executable includes two lines of JavaScript in a single HTML file, which triggers two payloads: "firebase-app-compat.js" and "firebase-analytics-compat.js." These are hosted on masquerading domains ("cdns3.51quickfox[.

]cn"), disguising them as official QuickFox sites ("51quickfox[. ]com").

"firebase-analytics-compat.js" is legitimate Firebase code, while "firebase-app-compat.js" is a heavily obfuscated payload that checks if the endpoint runs Windows, verifies it's not re-infected by checking with C2 servers, and displays a list of running processes using the "tasklist" command. This includes Xshell, MobaXterm, Tabby Terminal, Navicat, DBeaver, Git, IntelliJ IDEA, Sublime Text, Notepad++, Microsoft Visual Studio Code, Exodus Wallet, Binance, Ledger Live, Trezor Suite, Telegram, SafeW, Ai Fanyi, Haiwang Chuhai, Yi Fanyi, Kuai Fanyi, and HaiYiTong. The collected data includes the window title of the topmost active program, installed antivirus programs, .NET Framework runtime version, network and operating system details, current username, and specifics about the implant itself such as file path, version, process ID, and hosting process name.