Date: 09/24/2026
Severity: High
Summary
Researcher details a malicious Firefox extension masquerading as a PDF identity-verification utility that fetches its malicious payload only after installation to evade detection. The extension targets Google accounts, injecting an account-takeover script into legitimate accounts.google.com pages to automate authentication flows and capture Google OAuth session cookies. It can also manipulate password-reset flows to establish an attacker-controlled password, while exfiltrating stolen credentials/session data and live session telemetry to attacker infrastructure.
Indicators of Compromise (IOC) List
IP Address | pdf.gusercontent.com pdf.gusercontent.com/oninstalled pdf.gusercontent.com/loginSdk/assets/index-BhOgWOaO.js pdf.gusercontent.com/loginSdk/load-addon.js pdf.gusercontent.com/api/accounts/collect/?leadId=&email=&data= pdf.gusercontent.com/api/extlog pdf.gusercontent.com/reload |
Hash | f1b8329075b1cbd1ae0a5dc947bd00f94642cb166a86c2455a1d0b10aee9f2b1
16447c70f8e3c99de95b92846460214a661915c89f5c10965bf18da4c279880a
dc717b5ab9a8eccf6b6187880ba90b004cb00f503ff8bceb8405ccc33d1c6e3e
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "pdf.gusercontent.com" or url like "pdf.gusercontent.com" or siteurl like "pdf.gusercontent.com" |
Detection Query 2 : | sha256hash IN ("f1b8329075b1cbd1ae0a5dc947bd00f94642cb166a86c2455a1d0b10aee9f2b1","dc717b5ab9a8eccf6b6187880ba90b004cb00f503ff8bceb8405ccc33d1c6e3e","16447c70f8e3c99de95b92846460214a661915c89f5c10965bf18da4c279880a")
|
Reference:
https://socket.dev/blog/firefox-google-account-takeover