Extension Poisoning Campaign Highlights Gaps in Browser Security
ID: fc3c8009-7c6b-5ea0-94ca-afd93b20f744
STIX ID: report--fc3c8009-7c6b-5ea0-94ca-afd93b20f744
Feed Name: Dark Reading
Date Published: 2025-01-15
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A phishing attack on a Cyberhaven developer account allowed attackers to publish a malicious Chrome extension; researchers link this to two broader campaigns (one focused on stealing cookies/session tokens/credentials and another on telemetry/tracking) that affected dozens of extensions and an estimated 1.46 million users. The campaigns used phishing and a malicious OAuth application to take over developer accounts and distribute unauthorized updates between mid‑2023 and late‑2024; Google and researchers have removed many affected extensions and contained further spread but the incident highlights persistent browser-extension supply‑chain risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
