A Firefox extension masquerading as a PDF identity-verification tool can steal Google session cookies and automate account takeover, as revealed by Socket’s Threat Research team. The add-on, known as PDF Identity Verifier, was discovered in the Firefox Add-ons store on September 3, 2026. The case is noteworthy for its innovative design, as the files submitted to the store contain no hardcoded theft routines, account targets, or exfiltration addresses.
When installed, it waits five seconds before opening the PDF file from the lookalike domain, which is controlled by an attacker. Upon detecting a Set-Cookie header containing oauth_token, it forwards the cookie value, along with victim identifiers, to pdf.gusercontent.com/api/accounts/collect/.
A stolen session cookie allows an attacker to access an active account session, while setting an attacker-controlled password provides another route. The extension identifier is pdf-para-texto@extensao.local, which suggests an emphasis on Portuguese- and Spanish-speaking users despite a small reported install base. Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort.










