• News/
  • https://www.darkreading.com/endpoint-security/extension-poisoning-campaign-gaps-browser-security

Extension Poisoning Campaign Highlights Gaps in Browser Security

Dark Reading
·
Elizabeth Montalbano
·
Published Jan 15, 2025
·
Updated

A Christmas Eve phishing attack resulted in an unknown party taking over a Cyberhaven employee's Google Chrome Web Store account and publishing a malicious version of Cyberhaven's Chrome extension. While the problematic extension was removed within an hour of its discovery, the malicious activity highlights gaps in browser security that exist at most organizations and the necessity of getting a handle on the problem now, as extension poisoning is expected to be a persistent issue. Further research into the incident suggests that this attack was likely part of two separate, but potentially related, campaigns to target multiple extension developers to distribute malicious extensions, experts say. The campaigns may have begun as early as April 2023. "Currently we know about two different campaigns that have been targeting different objectives," says Amit Assaraf, CEO of Extension Total, a third-party extension security platform provider. Extension Total researchers have uncovered several malicious extensions over the past several weeks and have been looking at how they relate to each other. One campaign created extensions that steal cookies, session tokens, and possibly passwords, and targeted Facebook and OpenAI accounts, Assaraf says. The campaign relied on phishing to target extension developers and a malicious OAUTH application to take over Google Chrome Web Store accounts. Cyberhaven was one of the victims of this campaign. There is some disagreement among experts over when...

Read full article

Affected Software

6 affected components
Google Chrome Web Store
Cyberhaven Chrome extension
GPT 4 Summary with OpenAI
AI Assistant – ChatGPT and Gemini for Chrome
Google Chrome
Cyberhaven Chrome extension
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What event highlighted security gaps in browser extensions according to the article?

A Christmas Eve phishing attack compromised a Cyberhaven employee's Google Chrome Web Store account, leading to a malicious extension being published.

2

Which browser was involved in the extension poisoning incident?

The incident involved Google Chrome and its Chrome Web Store.

3

What extension was specifically targeted in the phishing attack?

The targeted extension was the Cyberhaven Chrome extension.

4

What type of attack was executed to compromise the account?

A phishing attack was used to take over the account of a Cyberhaven employee.

5

What was the outcome of the compromise for users of the affected extension?

Users of the malicious Cyberhaven Chrome extension were potentially exposed to security risks due to the installation of the harmful version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203