⛔ Malware Campaign Detected 2026-09-26
Confirmed malicious. codelake independently detected this at 2026-09-26 — codelake catch — the campaign was mapped from the Shadow Code publisher page after CLR-2026-3054; all four add-ons were already scanned in the codelake corpus (AMO recent feed, 2026-09-25).. Not yet in any public advisory database at detection time — codelake is the source of record. Static code + dataflow review of the published .xpi files; no execution.
Advisory · CLR-2026-3058

alihelp.xyz / Shadow Code — a Firefox affiliate-commission-hijacking campaign across four AliExpress add-ons

Four Firefox add-ons published by Shadow Code (AMO user 20125879) share one affiliate hijack: they redirect AliExpress pages to s.click.aliexpress.com with the same key _c4WvcFkP and tag connected_by=alihelp, backed by alihelp.xyz. Each is documented in its own advisory below.

MediumConfirmed maliciouscodelake first-catch
What connects them

All four add-ons are the same operation, not four coincidences. Shared fingerprint:

  • Same affiliate key AFF_SHORT_KEY = '_c4WvcFkP' and redirect tag connected_by=alihelp.
  • Same backend alihelp.xyz (config /api/ext, telemetry /api/track); GUIDs all end @alihelp.xyz.
  • Same publisher Shadow Code (AMO user 20125879); all declare data_collection: none in the manifest.
  • Code in the downloader references alihelp.xyz/admin's “Extension affiliate ID pool” and a shared alihelp-web lib/extensions.js registry — a centrally-managed, multi-extension affiliate operation.

The four add-ons

Shared indicators
🔑Affiliate key: _c4WvcFkP · redirect tag connected_by=alihelp
🌐Backend: alihelp.xyz — /api/ext (config), /api/track (product_click beacons)
🔗Injected deep link: s.click.aliexpress.com/deep_link.htm?aff_short_key=_c4WvcFkP&…
🧩GUID suffix @alihelp.xyz · Publisher “Shadow Code” (AMO user 20125879)

Verified by static code + dataflow review of the published .xpi files; no execution.

Each add-on has its own advisory; all four reported to Mozilla AMO.