logo

Security alert: Christmas Day Chrome extension compromise

ID: e6a4b75d-cbd1-576a-af57-db24547a5225

STIX ID: report--e6a4b75d-cbd1-576a-af57-db24547a5225

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2024-12-27

Date Updated: 2026-04-27

Author: Myles Satterfield

...
...

A threat actor phished an administrator at Cyberhaven to publish a malicious Chrome extension (version 24.10.4) to the Chrome Web Store on Dec 25, which, along with at least four other compromised extensions, collected and exfiltrated sensitive browser data (cookies, authenticated sessions) and Facebook Advertising account information to a C2 domain; Cyberhaven removed the malicious package within about an hour and has recommended users update to patched versions and rotate credentials and API tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.