Chrome security extension hacked to steal user data
At least five Chrome extensions have been compromised in a coordinated attack, where a threat actor successfully injected code that stole sensitive information from users.
This is according to cybersecurity experts at Cyberhaven. The US-based data security company warned its customers about a breach that occurred on December 24, following a successful phishing campaign targeting the company's administrator account on the Google Chrome Store.
Prominent among Cyberhaven's clients are popular brands such as Snowflake, Motorola, Canon, Reddit, AmeriHealth, Cooley, IVP, Navan, DBS, Upstart and Kirkland & Ellis.
Hackers took over employee accounts and released a malicious version (24.10.4) of the Cyberhaven extension, which included code that could steal authenticated sessions and cookies to the attacker's domain (cyberhavenext[.]pro).
Cyberhaven's internal security team removed the malware package within an hour of detection, the company said in an email to customers.
The clean version of the extension is v24.10.5 which was released on December 26. In addition to upgrading to the latest version, Cyberhaven Chrome extension users are advised to revoke non-FIDOv2 passwords, change all API tokens, and review browser logs to assess for malicious activity.
Many Chrome extensions have been hacked
Following Cyberhaven's disclosure, Nudge Security researcher Jaime Blasco conducted a deeper investigation, redirecting from the attacker's IP address and registered domain name.
According to Blasco, the malicious code that allowed the extension to receive commands from the attacker was also injected into other Chrome extensions at the same time:
- Internxt VPN – Free, Encrypted, Unlimited VPN for Secure Browsing. (10,000 users)
- VPNCity – Privacy-focused VPN with 256-bit AES encryption and global server coverage. (50,000 users)
- Uvoice – Rewards-based service to earn points through surveys and provide PC usage data. (40,000 users)
- ParrotTalks – A seamless text and note taking information search engine. (40,000 users)
- Blasco found multiple domains pointing to several other potential victims, but so far only the above extensions have been confirmed to contain malicious code.
Users of these extensions are advised to immediately remove them from their browsers or upgrade to a secure version released after December 26, after ensuring that the publisher is aware of the security issue and has fixed it.
If you are unsure, it is best to uninstall the extension, reset important account passwords, clear browser data, and reset browser settings to factory defaults.
You should read it
- Measures to enhance security on the iPad
- How to check your identity has been stolen yet?
- 7 mistakes make Internet security at risk
- 4 problems difficult for network security 2013
- Some basic website security rules
- Discovering more vulnerabilities makes Bluetooth devices vulnerable to malicious attacks
- Awareness and experience - the most important factor in every network security process
- 3 Chrome extensions enhance your security and safety
May be interested
- Reddit is hacked, many member data is stolenreddit has been attacked by hackers and stolen data including passwords, message content, personal information, etc. of the members between june 14 and june 18.
- The most detailed way to retrieve a hacked Facebook account in 2024how to retrieve a hacked facebook account is a solution that any user should know when participating in an increasingly complex online environment, full of user security risks. so are there any simple and effective ways to recover a hacked fb account? let's find out with free download.
- NoScript, a popular Firefox extension, is available for Chrome, invite download and experiencenoscript is a popular user privacy protection extension for firefox over the past 14 years.
- Instructions for installing extension for Chrome on a computer from a smartphoneif you are browsing the web on smartphones (both android and ios), you find a great utility for chrome and want to install it for the desktop without having to turn on the computer, follow the instructions below.
- Listed 15 Chrome Extension for programmerslet's tipsmake.com list 15 chrome extension for programmers in the article below!
- Hacker attacks Chrome utility to install malwarescammers recently hacked an extension on google chrome after capturing a chrome web store account of a group of german developers a9t9 and using it to send spam messages to users.
- 9 useful Chrome extensions for ChatGPTchatgpt is super hot lately, allowing you to find information about just about anything out there. if you're a chrome user, you'll be happy to know that there are many extensions that provide additional features for chatgpt right in your browser.
- Google 'tightens' the installation of the extension on Chrome browserextensions (extensions) power up the browser, but to avoid computer infections, google now only allows users to install extensions from the chrome web store online store.
- How to use the Chrome extension Trim to make Netflix betterpeople used to spend a lot of time scrolling through netflix, overwhelmed by decision fatigue and not knowing what to watch. but after finding the chrome extension trim, it completely changed their netflix experience.
- 5 Best Chrome Extensions That Google Just Removedin 2025, google discontinued a bunch of popular chrome extensions. if some of your favorite tools disappeared overnight, here's why—and we'll say goodbye to some of our best chrome extensions.