logo

Targeted supply chain attack against Chrome browser extensions

ID: 9b74b8f4-36db-5829-be01-4adcfe5afd1d

STIX ID: report--9b74b8f4-36db-5829-be01-4adcfe5afd1d

Feed Name: Sekoia.io Blog

Threat Score
88/100

Date Published: 2025-01-22

Date Updated: 2026-04-29

Author: Quentin Bourgue and Sekoia TDR

...
...

Sekoia documents a December 2024 supply-chain campaign where attackers used targeted spearphishing against Chrome extension developers to authorize a malicious OAuth application, enabling the adversary to push compromised updates to roughly a dozen extensions that potentially impacted hundreds of thousands of users; the injected JavaScript fetched remote configurations and exfiltrated API keys, session cookies and other tokens (notably for ChatGPT and Facebook Business), and the report includes detailed IoCs, attacker infrastructure mappings, and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.