logo

Breaking down a supply chain attack leveraging a malicious Google Workspace OAuth app

ID: d221d8b5-c61d-5df4-96b3-a467721f88ec

STIX ID: report--d221d8b5-c61d-5df4-96b3-a467721f88ec

Feed Name: Red Canary

Threat Score
90/100

Date Published: 2026-03-04

Date Updated: 2026-04-29

Author: Tre Wilkins

...
...

In late 2024 attackers executed a supply-chain campaign targeting Chrome extension developers by tricking them into consenting to a malicious Google OAuth app named "Privacy Policy Extension" that requested the chromewebstore scope. With that permission the adversary could modify and publish extensions in the Chrome Web Store; the compromised extensions were designed to harvest session cookies and authentication tokens (notably for Facebook Ads accounts), impacting over 2.6 million users. The report models detection and remediation steps using Google Workspace audit events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.