Malicious Firefox Extension Poses as PDF Identity Verifier to Hijack Google Accounts
Brief
Socket identified a Firefox extension that ships with no hardcoded malicious code and fetches a remote payload after installation to silently automate Google account takeover, targeting Portuguese- and Spanish-speaking users since September 11, 2026. Socket's Threat Research team identified a malicious Firefox extension posing as a utility for identity verification before opening protected PDF documents.
The extension, pdf-para-texto@extensao. local , was published to the Firefox Add-ons store on September 3, 2026, and its malicious functionality was first introduced in version 1. 4 on September 11, 2026.
The extension does not have a significant user base, and the expected impact is fairly low.
