This document discusses the risks of malicious browser extensions and demonstrates a proof of concept homemade Firefox extension created by the author that is capable of command and control, stealing cookies and passwords, uploading and downloading files, executing binary code, bypassing geolocation restrictions, and remaining undetected by antivirus software. The author argues that browser extensions pose serious risks and outlines recommendations for browser developers, website developers, antivirus companies, companies, and users to help mitigate these risks.