tech
Published 2026-09-23
Verified 2026-09-27

Malicious Firefox PDF “identity verifier” extension (pdf-para-texto@extensao.local) steals Google sessions (Socket 23 Sep)

Socket Threat Research (23 September 2026) documents a Firefox Add-ons store extension posing as a PDF identity-verification tool (addon id pdf-para-texto@extensao.local). Published 3 September 2026; version 1.4 turned malicious on 11 September 2026. Shipped store code has no hardcoded targets or exfiltration endpoints — five seconds after install it opens an attacker page that bridges remote config into the extension, then injects an automated account-takeover script into real accounts.google.com flows, capturing Google session cookies and, when prompted, attacker-controlled password-reset values; also alters passkey checks. Targets mainly Portuguese- and Spanish-speaking users; Socket notes a small user base / fairly low expected impact but highlights the post-install payload pattern. Primary: Socket blog; wire: Cyber Security News 24 Sep amplify.

Product
Mozilla Firefox (malicious Add-ons store extension pdf-para-texto@extensao.local)
Versions
Malicious from extension version 1.4 (11 Sep 2026); first published 3 Sep 2026
Exploited in Australia?
unknown
Patch to
Remove pdf-para-texto@extensao.local if installed; review Firefox extensions (especially PDF/identity tools); force Google sign-out / revoke sessions and rotate passwords/passkeys for exposed accounts; prefer enterprise extension allow-lists

Primary: Socket — Malicious Firefox extension hijacks Google accounts (23 Sep 2026) · Vendor: Socket Threat Research · Cyber Security News — Firefox PDF-tool extension steals Google sessions (24 Sep 2026)

tech australia identity