logo

Chrome Extension Compromises Highlight Software Supply Challenges

ID: 94aab147-3394-5f9d-9a27-f2f55e3b0545

STIX ID: report--94aab147-3394-5f9d-9a27-f2f55e3b0545

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-01-03

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

On Christmas Eve attackers used OAuth-based developer phishing to hijack the publishing rights of Chrome extensions and push malicious updates that could exfiltrate cookies and Facebook access tokens and install click-listeners to potentially bypass CAPTCHAs. Cyberhaven detected and removed a compromised extension after about a day; investigators link the techniques or infrastructure to roughly 36 extensions and up to 2.6 million users, and the report warns of growing supply-chain risk and recommends monitoring, peer review of releases, and improved email/security hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.