Fake Firefox PDF Extension Steals Google Session Cookies and Can Silently Reset Passwords
A Firefox add-on posing as a PDF identity-verification tool loads attacker configuration from pdf.gusercontent.com after install, steals Google oauth_token cookies, and can automate password resets behind a full-screen overlay; impact assessed as low due to a…
Socket identified a Firefox add-on named PDF Identity Verifier (ID: pdf-para-texto@extensao.local) that was published on Firefox Add-ons on September 3, 2026, and became malicious in version 1.4 released on September 11, 2026. The extension appears benign in static review because its malicious logic arrives as remote configuration rather than packaged code: after installation it loads attacker-supplied settings from pdf.gusercontent.com. It monitors Google traffic and captures Set-Cookie values containing oauth_token, enabling session hijacking without stealing passwords first. It can also inject automation into accounts.google.com to drive recovery flows and set a new password, hidden behind a full-screen overlay rendered on top of Google's real sign-in flow. Lures use a protected-PDF pretext and are delivered in Portuguese, Spanish, and English, mainly targeting Portuguese- and Spanish-speaking users. Socket reported a small user base; both reports assess immediate impact as low (Report 1: "no substantial user base"; Report 2: "fairly low"). Recommended actions are to remove the add-on and revoke active Google sessions; defenders should hunt for pdf.gusercontent.com and broad webRequest permissions.
- Extension: Firefox add-on 'PDF Identity Verifier', ID pdf-para-texto@extensao.local, discovered by Socket.
- Listed on Firefox Add-ons on September 3, 2026; version 1.4, released September 11, 2026, introduced the malicious behavior.
- Malicious logic is delivered as remote configuration fetched from pdf.gusercontent.com (defanged) after install, not as packaged code, which is why it looks benign in static review.
- Steals Google Set-Cookie values containing oauth_token for session hijacking without needing the user's password.
- Can inject automation into accounts.google.com to drive recovery flows and submit a new password, concealed by a full-screen overlay on Google's genuine sign-in flow.
- Lure uses a protected-PDF pretext in Portuguese, Spanish, and English (Report 1); Report 2 states the campaign mainly targets Portuguese- and Spanish-speaking users.
- Socket reports a small user base; both sources assess immediate impact as low.
- Mitigations: remove the add-on and revoke Google sessions; detection guidance includes hunting for pdf.gusercontent.com and broad webRequest permissions.
Coverage timelineoldest first · each row is one article
- · 3d agoFake Firefox Extension Hijacks Google Accounts Without Stealing Passwords First
GBHackers· 52
A fake Firefox PDF extension steals Google oauth_token cookies and automates account takeover after install.
- · 3d agoMalicious Firefox Extension Disguised as PDF Tool Steals Google Account Sessions
Cyber Security News· 58
A Firefox PDF add-on fetches post-install instructions that steal Google sessions and can silently reset passwords.