Fake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First
A fake Firefox PDF extension steals Google oauth_token cookies and automates account takeover after install.
Socket found a Firefox add-on posing as a PDF identity-verification tool that looks benign in static review, then loads attacker configuration from pdf.gusercontent.com after install. Published on September 3, 2026, it gained malicious behavior in version 1.4 on September 11. It captures Google Set-Cookie values containing oauth_token and can inject automation into accounts.google.com to drive recovery flows and set a new password. Immediate impact is assessed as low because the extension has no substantial user base; lures support Portuguese, Spanish, and English.
52