Chrome Extension Compromises Highlight Software Supply Challenges
ID: 94aab147-3394-5f9d-9a27-f2f55e3b0545
STIX ID: report--94aab147-3394-5f9d-9a27-f2f55e3b0545
Feed Name: Dark Reading
On Christmas Eve attackers used OAuth-based developer phishing to hijack the publishing rights of Chrome extensions and push malicious updates that could exfiltrate cookies and Facebook access tokens and install click-listeners to potentially bypass CAPTCHAs. Cyberhaven detected and removed a compromised extension after about a day; investigators link the techniques or infrastructure to roughly 36 extensions and up to 2.6 million users, and the report warns of growing supply-chain risk and recommends monitoring, peer review of releases, and improved email/security hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
