Malicious Firefox Extension Uses Remote Payload to Hijack Google Accounts

· Original article ↗

Summary

Socket says a Firefox extension posing as a PDF identity verifier downloads its malicious configuration after installation, then targets Google sessions and credentials. The campaign has targeted Portuguese- and Spanish-speaking users since September 11, 2026.

Key points

  • The extension, PDF Identity Verifier (pdf-para-texto@extensao.local), was published to Firefox Add-ons on September 3, 2026; its malicious behavior appeared in version 1.4 on September 11.
  • The shipped code lacks hardcoded malicious logic. After installation, a lookalike gusercontent[.]com domain delivers configuration and payloads that arm the extension.
  • The extension injects a script into real accounts.google.com pages, automates Google's sign-in flow, and can change a victim's password if prompted to reset it.
  • It captures Google Set-Cookie headers containing oauth_token and sends the token, victim identifiers, and session activity to attacker-controlled endpoints.
  • The lure and interface target Portuguese- and Spanish-speaking users. Socket says the extension has few users and expected impact is low.
  • Socket recommends removing the extension, revoking Google sessions and tokens, resetting credentials from a clean device, reviewing account security, and blocking the attacker's infrastructure.

Article Details

Attack Vectors
  • A Firefox extension posing as a PDF identity-verification utility opens an attacker-controlled landing page after installation. The page supplies configuration and payload code absent from the extension's shipped files.
  • The supplied configuration enables the extension to inject an account-takeover script into genuine accounts.google.com pages and monitor Google response headers for an oauth_token cookie.
  • The injected script conceals sign-in automation with a fake validation overlay, attempts to navigate passkey and security-key challenges, and sets an attacker-known password if Google's flow requires a password reset.
  • The extension sends captured cookies and victim identifiers to an attacker-controlled collection endpoint. The injected script also sends a live transcript of page text and interactive elements to a logging endpoint.
Defensive Notes
  • Uninstall PDF Identity Verifier and block the extension identifier pdf-para-texto@extensao.local through browser-management policies.
  • From a trusted device, terminate affected Google sessions, revoke active sessions and tokens, change the password, and review passkeys, security keys, recovery details, and multifactor-authentication methods.
  • Review Google security events, login history, connected applications, forwarding rules, delegated access, recovery changes, and associated account activity.
  • Hunt for and block requests to the reported attacker-controlled infrastructure and inspect Firefox profiles for the extension identifier, local-storage data, and installation records. Treat affected profiles as compromised.

Indicators of compromise

TypeIndicatorContext
DOMAINpdf[.]gusercontent[.]comAttacker-controlled lookalike domain identified as C2 infrastructure.
SHA25616447c70f8e3c99de95b92846460214a661915c89f5c10965bf18da4c279880aFile hash of the loader payload script.
SHA256dc717b5ab9a8eccf6b6187880ba90b004cb00f503ff8bceb8405ccc33d1c6e3eFile hash of the Google account-takeover payload.
SHA256f1b8329075b1cbd1ae0a5dc947bd00f94642cb166a86c2455a1d0b10aee9f2b1File hash of the attacker-controlled onInstalled landing page.
URLhxxps[:]//pdf[.]gusercontent[.]com/api/accounts/collect/?leadId=Attacker-controlled collection URL prefix supplied in the extension's runtime configuration.
URLhxxps[:]//pdf[.]gusercontent[.]com/oninstalledAttacker-controlled installation landing page specified in the extension code.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles