Firefox PDF-Themed Add-on Hijacks Google Sessions

A newly discovered Firefox extension poses as a PDF protection tool but turns malicious shortly after installation to hijack Google account sessions. Appearing in the Firefox Add-ons store on September 3, 2026, the add-on—version 1.4—began its harmful behavior eight days later, on September 11. It is designed to stealthily take over accounts without obvious signs during initial reviews.

How the Extension Operates

At first glance, the extension appears benign, requesting permissions typical for a PDF identity or protected document checker—access to storage, network communication, and Google pages—without any obvious triggers for wrongdoing. Once installed, however, it contacts an external attacker domain disguised as part of Google infrastructure. A page that resembles a legitimate Google‐hosted interface loads, delivering instructions through a message bridge to the extension’s background script. From that moment, the add-on starts monitoring Google traffic for session cookies and other credentials.

Within seconds post-install, the user is redirected to what looks like Google’s genuine sign-in page, though a malicious script is already injected. Overlay windows force passkey or security key challenges, and scripts run in the background fetch and transmit session data and content from pages visited. If Google’s safeguards prompt for password recovery, the add-on quietly generates and submits a new password, capturing that information for the attacker as an alternate access path.

Targeting and Risk Level

The attack is particularly aimed at Spanish- and Portuguese-speaking users, using the familiar PDF identity-verification theme as bait. Because the extension only arms itself post-approval in the store, initial reviews fail to detect anything malicious—no hardcoded payloads or overt cookie stealing until activation. One security firm that uncovered this operation estimates that while the extension has a relatively small number of installs, the account takeover potential is significant.

Indicators of compromise include the add-on ID “[email protected]”, as well as a cluster of domains and URLs used for configuration, payload injection, session token exfiltration, and telemetry. Even the extension’s SHA-256 hashes for key scripts and payloads have been identified—useful for defense or detection efforts.

Mitigation Steps and Detection

If you have this extension installed, remove it immediately. Next, use a trusted device to sign out of all Google sessions, change your password, and revoke any tokens or devices that shouldn’t have access. Also review alert logs for unexpected password resets, recovery email changes, forwarding rules, or odd new authentication devices. Every connected app and setting should be audited carefully.

For administrators or security professionals, the warning signs include unexpected activity in Firefox extension settings, traffic to attacker-controlled infrastructure, and overlays that intercept reset flows. Even after removal, some artifacts may linger—consider affected browser profiles compromised if they exhibit suspicious behavior.

This kind of stealth attack adds to a growing pattern of malicious extensions using trustworthy fronts and PDF-themed lures to gain sensitive account access without early detection.

Why this matters: PDF identity or document tools are common enough that users and automated review systems often trust them without scrutiny. This extension exploited that trust, turning hidden code into a powerful account takeover vector. What to watch now: tighter vetting of extension post-install behavior, improved detection of script injections, and monitoring for surprise password resets or unknown recovery actions in Google accounts. The success of such an attack—despite low installation numbers—shows how blurry the boundary is between utility and threat, and why vigilance must apply long after an add-on receives approval.