Malicious Firefox Extension Uses Remote Payload to Hijack Google Accounts

Summary
Socket says a Firefox extension posing as a PDF identity verifier downloads its malicious configuration after installation, then targets Google sessions and credentials. The campaign has targeted Portuguese- and Spanish-speaking users since September 11, 2026.
Key points
- The extension, PDF Identity Verifier (pdf-para-texto@extensao.local), was published to Firefox Add-ons on September 3, 2026; its malicious behavior appeared in version 1.4 on September 11.
- The shipped code lacks hardcoded malicious logic. After installation, a lookalike gusercontent[.]com domain delivers configuration and payloads that arm the extension.
- The extension injects a script into real accounts.google.com pages, automates Google's sign-in flow, and can change a victim's password if prompted to reset it.
- It captures Google Set-Cookie headers containing oauth_token and sends the token, victim identifiers, and session activity to attacker-controlled endpoints.
- The lure and interface target Portuguese- and Spanish-speaking users. Socket says the extension has few users and expected impact is low.
- Socket recommends removing the extension, revoking Google sessions and tokens, resetting credentials from a clean device, reviewing account security, and blocking the attacker's infrastructure.
Article Details
- Attack Vectors
- A Firefox extension posing as a PDF identity-verification utility opens an attacker-controlled landing page after installation. The page supplies configuration and payload code absent from the extension's shipped files.
- The supplied configuration enables the extension to inject an account-takeover script into genuine accounts.google.com pages and monitor Google response headers for an oauth_token cookie.
- The injected script conceals sign-in automation with a fake validation overlay, attempts to navigate passkey and security-key challenges, and sets an attacker-known password if Google's flow requires a password reset.
- The extension sends captured cookies and victim identifiers to an attacker-controlled collection endpoint. The injected script also sends a live transcript of page text and interactive elements to a logging endpoint.
- Defensive Notes
- Uninstall PDF Identity Verifier and block the extension identifier pdf-para-texto@extensao.local through browser-management policies.
- From a trusted device, terminate affected Google sessions, revoke active sessions and tokens, change the password, and review passkeys, security keys, recovery details, and multifactor-authentication methods.
- Review Google security events, login history, connected applications, forwarding rules, delegated access, recovery changes, and associated account activity.
- Hunt for and block requests to the reported attacker-controlled infrastructure and inspect Firefox profiles for the extension identifier, local-storage data, and installation records. Treat affected profiles as compromised.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | pdf[.]gusercontent[.]com | Attacker-controlled lookalike domain identified as C2 infrastructure. |
| SHA256 | 16447c70f8e3c99de95b92846460214a661915c89f5c10965bf18da4c279880a | File hash of the loader payload script. |
| SHA256 | dc717b5ab9a8eccf6b6187880ba90b004cb00f503ff8bceb8405ccc33d1c6e3e | File hash of the Google account-takeover payload. |
| SHA256 | f1b8329075b1cbd1ae0a5dc947bd00f94642cb166a86c2455a1d0b10aee9f2b1 | File hash of the attacker-controlled onInstalled landing page. |
| URL | hxxps[:]//pdf[.]gusercontent[.]com/api/accounts/collect/?leadId= | Attacker-controlled collection URL prefix supplied in the extension's runtime configuration. |
| URL | hxxps[:]//pdf[.]gusercontent[.]com/oninstalled | Attacker-controlled installation landing page specified in the extension code. |
MITRE ATT&CK
T1036 · MasqueradingThe malicious extension presents itself as a PDF identity-verification utility.T1098 · Account ManipulationWhen Google's flow requires a password reset, the injected script sets and submits a password known to the attacker.T1176.001 · Browser ExtensionsThe malicious Firefox extension uses browser permissions and a post-install configuration to monitor responses and inject account-takeover code into tabs.T1185 · Browser Session HijackingAn injected script uses the victim's authenticated Google browser session to automate an account-takeover flow.T1539 · Steal Web Session CookieThe extension captures Set-Cookie response-header values containing oauth_token and sends the cookie values to an attacker-controlled endpoint.