logo

SquareX Researchers Expose OAuth Attack on Chrome Extensions Days Before Major Breach

ID: 491c5ba6-0f95-58e8-89a3-e1ebd0e42d63

STIX ID: report--491c5ba6-0f95-58e8-89a3-e1ebd0e42d63

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-12-30

Date Updated: 2026-04-22

Author: CyberNewswire

...
...

**Executive summary:** A malicious update to Cyberhaven’s Chrome extension was published to the Chrome Web Store on 25 December 2024 after attackers phished extension developers to grant OAuth permissions, enabling session hijacking and exfiltration of credentials across multiple sites; the malicious build was live for over 30 hours and the extension had roughly 400,000 users, illustrating a high-impact supply-chain campaign against browser extensions and a wider trend identified by SquareX.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.