| Scenario | Action needed |
|---|---|
| Fedora 42 and earlier, RHEL, Rocky Linux, AlmaLinux | dnf on these releases cannot replace the key automatically. Updates fail with errors like "Import of the key didn't help, wrong key?" or "The GPG keys listed for the mozilla repository are already installed but they are not correct for this package." Users must manually remove the old key and import the new one . |
| openSUSE / SUSE-based distributions | zypper cannot replace the key on its own. Updates fail with "Signature verification failed" or "NOKEY." Same manual removal and import required . |
| Fedora 43 and later | No special action. dnf downloads the updated key during the next update; the user just confirms the fingerprint matches 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3 . |
| Anyone who manually verifies GPG signatures | Must import the new signing key and the revocation for the old key . |
| Thunderbird RPM users | No RPM-specific action needed — Thunderbird does not provide official RPM packages . |
The manual removal command (for affected distros):
sudo rpm -e --allmatches gpg-pubkey-14f26682d0916cdd81e37b6d61b7b526d98f0353
sudo rpm --import https://packages.mozilla.org/rpm/firefox/signing-key.gpg
Followed by sudo dnf clean all (Fedora/RHEL) or sudo zypper refresh (openSUSE/SUSE) .
This incident occurred less than a week after the massive keyv npm package hijacking (ChainDrop) disclosed on August 4, 2026 . In that attack, a threat group (TeamPCP) compromised the GitHub account of the maintainer behind keyv, cacheable, and related npm packages, publishing malicious versions that deployed a self-propagating credential-stealing worm (Shai-Hulud) that spread to over 2,251 versions of 452 unique packages . The Mozilla incident highlights a different but equally urgent supply chain risk: accidental exposure of signing keys via human error in internal repositories, rather than external account compromise. Taken together, the two events underscore that software supply chain integrity faces threats from both deliberate hijacking (keyv) and inadvertent credential leaks (Mozilla) — and that both can force large-scale rotations, disrupt verification chains, and impose manual remediation on downstream users.