Targeted supply chain attack against Chrome browser extensions
ID: 9b74b8f4-36db-5829-be01-4adcfe5afd1d
STIX ID: report--9b74b8f4-36db-5829-be01-4adcfe5afd1d
Feed Name: Sekoia.io Blog
Date Published: 2025-01-22
Date Updated: 2026-04-29
Author: Quentin Bourgue and Sekoia TDR
Sekoia documents a December 2024 supply-chain campaign where attackers used targeted spearphishing against Chrome extension developers to authorize a malicious OAuth application, enabling the adversary to push compromised updates to roughly a dozen extensions that potentially impacted hundreds of thousands of users; the injected JavaScript fetched remote configurations and exfiltrated API keys, session cookies and other tokens (notably for ChatGPT and Facebook Business), and the report includes detailed IoCs, attacker infrastructure mappings, and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
