Targeted supply chain attack against Chrome browser extensions
ID: 51fa51c9-663e-5cdd-a9ff-09999d9f33f9
STIX ID: report--51fa51c9-663e-5cdd-a9ff-09999d9f33f9
Feed Name: Sekoia.com
Sekoia describes a December 2024 supply-chain campaign where attackers phished Chrome extension developers to authorize a malicious OAuth app, used it to publish compromised updates to roughly a dozen extensions (potentially impacting hundreds of thousands of users), and injected scripts to harvest API keys, session cookies and other authentication data from services such as ChatGPT and Facebook Business; the report details the malicious code, attacker infrastructure, IoCs and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
