logo

Extension Poisoning Campaign Highlights Gaps in Browser Security

ID: fc3c8009-7c6b-5ea0-94ca-afd93b20f744

STIX ID: report--fc3c8009-7c6b-5ea0-94ca-afd93b20f744

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-15

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

A phishing attack on a Cyberhaven developer account allowed attackers to publish a malicious Chrome extension; researchers link this to two broader campaigns (one focused on stealing cookies/session tokens/credentials and another on telemetry/tracking) that affected dozens of extensions and an estimated 1.46 million users. The campaigns used phishing and a malicious OAuth application to take over developer accounts and distribute unauthorized updates between mid‑2023 and late‑2024; Google and researchers have removed many affected extensions and contained further spread but the incident highlights persistent browser-extension supply‑chain risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.