TechRadar News.
Technology

Firefox Extension for PDF Access Discovered as Google Session Hijacker

Firefox Extension for PDF Access Discovered as Google Session Hijacker

Researchers have uncovered that a Firefox add‑on advertised as a tool for viewing locked PDF documents serves as a vehicle for exfiltrating Google account sessions. After the extension is added, it can convert a browser already logged into Google into a channel that lets attackers seize the account unnoticed.

The harmful script is intentionally minimal. In its first inspection it carries just enough code to fetch further instructions from an external server once the user selects “Add to Firefox.” By postponing the download, the add‑on presents little dubious code for both automated tools and human auditors, enabling it to clear Mozilla’s extension store review.

After the secondary payload is obtained, the add‑on pulls the authentication cookies Google relies on to keep a session active. It then forwards those cookies to a command‑and‑control server, permitting an attacker to masquerade as the victim across Gmail, Drive, Calendar and other services. Since the compromise targets the session rather than the password, two‑factor authentication is effectively sidestepped.

This case underscores an expanding pattern of browser‑extension misuse, in which creators cloak malicious functions behind innocuous‑sounding titles and postpone the retrieval of dangerous modules until after the extension is installed. Comparable tactics have appeared in Chrome and Edge environments, leading security analysts to urge more dynamic extension analysis and tighter scrutiny of post‑install network calls.

In response, Mozilla has pulled the add‑on from its store and warned users to delete any installed copies. The firm also announced a review of its rules regarding delayed code execution and is weighing extra protective measures. Users should only add extensions from reputable developers, periodically check their add‑on inventory, and keep an eye on active sessions via Google’s account security dashboard.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related