A malicious Firefox extension masquerading as a PDF identity-verification utility has been found targeting Google accounts through session-cookie theft and automated account-takeover activity. The campaign is notable because the add-on initially contains no obvious credential-stealing code, malicious URLs, or hardcoded payloads, allowing it to appear benign during basic static analysis. Malicious functionality was introduced in […]
Read the original article:
