VYPR
researchPublished Sep 24, 2026· 1 source

Malicious Firefox Extension Steals Google Account Sessions by Hiding Payload

A malicious Firefox extension disguised as a PDF tool has been found stealing active Google account sessions by capturing cookies and potentially resetting passwords after installation.

A new threat has emerged from the Firefox Add-ons store: a malicious extension that masquerades as a utility for opening protected PDF documents but secretly steals active Google account sessions. This add-on, which first appeared on September 3, 2026, and became malicious on September 11 with version 1.4, employs a sophisticated evasion technique by downloading its malicious payload only after installation. This delayed execution allows it to bypass initial security reviews that might flag suspicious code present from the outset.

The extension specifically targets users of Google services, aiming to capture active session cookies and, in certain circumstances, silently reset account passwords. Security analysts at Socket.dev identified the extension and detailed its post-installation attack vector. While the user base is reported to be small, the potential for account takeover remains a significant concern, particularly for Portuguese- and Spanish-speaking users who appear to be the primary targets, lured by the promise of a PDF identity-checking tool.

This method of hiding malicious intent until after installation is a recurring tactic used by threat actors to circumvent security measures. The extension requests permissions such as storage, network requests, and access to Google pages, which can appear legitimate for a PDF tool. However, it also alters browser passkey checks, a subtle indicator of its malicious nature.

Shortly after installation, the extension initiates its attack by opening an attacker-controlled page that mimics a Google-hosted service. A script from this page communicates with the extension via a message bridge, delivering the necessary instructions for the attack. This post-installation payload delivery is a key element in its stealth.

The attacker page then uses Google's genuine sign-in interface to identify the user's active Google account. It injects a specially crafted account takeover script into the victim's browser session. A full-screen validation message is displayed to obscure the automated steps the script takes through Google's legitimate account recovery process, including handling bot detection and security key challenges.

Crucially, the extension monitors Google responses for session cookies and exfiltrates these tokens, along with account details, to the attacker's infrastructure. This allows for account takeover even without the user's original password. In cases where Google's security prompts a password reset, the script can automatically generate and submit a new password, further compromising the account.

Socket.dev has provided indicators of compromise (IoCs), including the extension ID ('[email protected]') and various domains and file hashes associated with the attack infrastructure. Users who have installed the extension are advised to remove it immediately, sign out of all Google sessions from a trusted device, revoke active tokens, change their account password, and thoroughly review recent sign-in activity, connected apps, and recovery settings.

This incident serves as a stark reminder that seemingly innocuous browser extensions can pose significant security risks. The tactic of disguising malicious functionality until after installation highlights the ongoing cat-and-mouse game between threat actors and security vendors, emphasizing the need for vigilant user behavior and robust post-installation security monitoring.

Synthesized by Vypr AI
Malicious Firefox Extension Steals Google Account Sessions by Hiding Payload · VYPR