The document discusses the history and risks of malicious browser extensions. It begins with a brief history of malicious Firefox extensions from 2004-2012, noting a rise from 5 to 48 detected extensions between 2011-2012. Examples are shown of extensions that can steal cookies, passwords, files and execute binaries on the host system. Live demos are presented of proof-of-concept extensions developed for Firefox, Chrome, and Safari that demonstrate these risks. The document concludes by noting limitations of these extensions and providing recommendations to browser developers, antivirus companies, website developers and users to help mitigate these risks.