Google has removed "PDF QuickView" from the Chrome Web Store after threat research confirmed it contained obfuscated background scripts exfiltrating OAuth tokens for Google Workspace and Microsoft 365.
Malicious Chrome Extension "PDF QuickView" Stealing Session Tokens
Indicators of Compromise (IOCs)1 indicator
C2 Domainanalytics-pdf-helper.com
Tags:browser-extensionstealerchromesession-hijacking