logo

New details reveal how hackers hijacked 35 Google Chrome extensions

ID: e8ba3fcf-a1ae-5489-a750-1c69d359f8da

STIX ID: report--e8ba3fcf-a1ae-5489-a750-1c69d359f8da

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-12-31

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A phishing campaign targeted Chrome extension developers with deceptive emails that led them to authorize a malicious OAuth application named “Privacy Policy Extension.” By abusing the OAuth consent flow (bypassing MFA protections), attackers gained control of developers' Chrome Web Store accounts, pushed updates containing 'worker.js' and 'content.js' to at least 35 extensions (≈2.6M users), and exfiltrated Facebook credentials, access tokens, cookies, ad and business account data to attacker C2 servers; the report includes phishing domains, earlier tested subdomains, and technical indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.