logo

Time to check if you ran any of these 33 malicious Chrome extensions

ID: 7c1d5630-078e-5a27-9e42-ec1ddc64cd79

STIX ID: report--7c1d5630-078e-5a27-9e42-ec1ddc64cd79

Feed Name: Ars Technica Security

Threat Score
75/100

Date Published: 2025-01-03

Date Updated: 2026-04-19

Author: Dan Goodin

...
...

A spear-phishing campaign targeted Chrome extension developers and tricked at least one developer into granting OAuth permissions that allowed the attacker to push malicious extension updates; the campaign impacted 20 extensions with a combined ~1.46M downloads (including a malicious Cyberhaven extension update) and included an earlier, separate compromise of Reader Mode via a third‑party monetization library that harvested browsing data and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.