logo

SquareX Researchers Expose OAuth Attack on Chrome Extensions Days Before Major Breach

ID: b20a7aae-983b-59bb-939c-f6f3d54c9195

STIX ID: report--b20a7aae-983b-59bb-939c-f6f3d54c9195

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2024-12-30

Date Updated: 2026-04-26

...
...

SquareX disclosed a series of OAuth-based phishing attacks targeting Chrome Extension developers that enabled attackers to hijack developer accounts and publish malicious updates; a malicious version of the Cyberhaven extension was briefly available on the Chrome Store (over 400,000 users) and was used to steal credentials and exfiltrate sensitive information. SquareX had demonstrated similar extension abuse techniques days earlier (MV3 extension misuse to steal cookies, video streams, and add silent collaborators), and recommends organizations monitor and block unauthorized OAuth interactions and suspicious extension updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.