logo

Supply chain attack hits Chrome extensions, could expose millions

ID: 8db14fa0-28b4-5e4e-bd2e-933124cf101e

STIX ID: report--8db14fa0-28b4-5e4e-bd2e-933124cf101e

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-01-22

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers (Sekoia, Booz Allen Hamilton and vendors) describe a supply-chain phishing campaign that impersonated Chrome Web Store Developer Support to trick extension developers into granting a malicious OAuth app access, allowing attackers to push compromised extension updates that harvested API keys, session cookies and other authentication tokens. Dozens of developer accounts were compromised, impacting extensions with potentially hundreds of thousands to millions of users; researchers traced infrastructure to consistent domains and C2 hosts, linking activity back to at least December 2023 and reporting active exploitation in December 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.