Security alert: Christmas Day Chrome extension compromise
ID: e6a4b75d-cbd1-576a-af57-db24547a5225
STIX ID: report--e6a4b75d-cbd1-576a-af57-db24547a5225
Feed Name: Expel Blog
A threat actor phished an administrator at Cyberhaven to publish a malicious Chrome extension (version 24.10.4) to the Chrome Web Store on Dec 25, which, along with at least four other compromised extensions, collected and exfiltrated sensitive browser data (cookies, authenticated sessions) and Facebook Advertising account information to a C2 domain; Cyberhaven removed the malicious package within about an hour and has recommended users update to patched versions and rotate credentials and API tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
