logo

Targeted supply chain attack against Chrome browser extensions

ID: 51fa51c9-663e-5cdd-a9ff-09999d9f33f9

STIX ID: report--51fa51c9-663e-5cdd-a9ff-09999d9f33f9

Feed Name: Sekoia.com

Threat Score
88/100

Date Published: 2025-01-22

Date Updated: 2026-07-20

...
...

Sekoia describes a December 2024 supply-chain campaign where attackers phished Chrome extension developers to authorize a malicious OAuth app, used it to publish compromised updates to roughly a dozen extensions (potentially impacting hundreds of thousands of users), and injected scripts to harvest API keys, session cookies and other authentication data from services such as ChatGPT and Facebook Business; the report details the malicious code, attacker infrastructure, IoCs and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.