Supply chain attack hits Chrome extensions, could expose millions
ID: 8db14fa0-28b4-5e4e-bd2e-933124cf101e
STIX ID: report--8db14fa0-28b4-5e4e-bd2e-933124cf101e
Feed Name: The Register (Security)
Security researchers (Sekoia, Booz Allen Hamilton and vendors) describe a supply-chain phishing campaign that impersonated Chrome Web Store Developer Support to trick extension developers into granting a malicious OAuth app access, allowing attackers to push compromised extension updates that harvested API keys, session cookies and other authentication tokens. Dozens of developer accounts were compromised, impacting extensions with potentially hundreds of thousands to millions of users; researchers traced infrastructure to consistent domains and C2 hosts, linking activity back to at least December 2023 and reporting active exploitation in December 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
