← Back to feed
Breaches & RansomwareEmerging1 sourceSep 23, 2026 · 21:37via Socket Security Blog

Malicious Firefox Extension Poses as PDF Identity Verifier to Hijack Google Accounts

Brief

Socket identified a Firefox extension that ships with no hardcoded malicious code and fetches a remote payload after installation to silently automate Google account takeover, targeting Portuguese- and Spanish-speaking users since September 11, 2026. Socket's Threat Research team identified a malicious Firefox extension posing as a utility for identity verification before opening protected PDF documents.

The extension, pdf-para-texto@extensao. local , was published to the Firefox Add-ons store on September 3, 2026, and its malicious functionality was first introduced in version 1. 4 on September 11, 2026.

The extension does not have a significant user base, and the expected impact is fairly low.

Read more on Socket Security Blog