• News/
  • https://www.theregister.com/2025/01/22/supply_chain_attack_chrome_extension/

Supply chain attack hits Chrome extensions, could expose millions

The Register
·
Connor Jones
·
Published Jan 22, 2025
·
Updated

Cybersecurity outfit Sekoia is warning Chrome users of a supply chain attack targeting browser extension developers that has potentially impacted hundreds of thousands of individuals already. Dozens of Chrome extension developers have fallen victim to the attacks thus far, which aimed to lift API keys, session cookies, and other authentication tokens from websites such as ChatGPT and Facebook for Business. Sekoia examined the infrastructure used for the wide-scale phishing campaign targeting devs and traced it back to similar attacks as far back as 2023 with "high confidence." The latest known campaign activity occurred on December 30, 2024, however. Among the victims was California-based Cyberhaven, which makes a cloud-based data protection tool. The company was one of the unfortunate ones to detect the compromise over the holiday period on Boxing Day 2024 – a discovery that was widely reported at the time. Booz Allen Hamilton analyzed the incident at Cyberhaven and backed up the vendor's suspicions that it was part of a wider campaign. Its accompanying report [PDF] to the Cyberhaven analysis revealed a long list of other extensions it believes were likely affected, taking the potential number of affected end users into the millions. Sekoia published a less comprehensive list in its research, although the same extensions appear on both lists. A number of the potentially affected extensions (according to Booz Allen Hamilton's report) appear to have been pulled from the Chrome...

Read full article

Affected Software

4 affected components
Reader Mode extension=1.5.7
Reader Mode extension=1.5.9
Google Chrome
Cyberhaven data protection tool
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a supply chain attack that has impacted Chrome extensions, potentially affecting hundreds of thousands of users.

2

What security implications are discussed in the article?

The article warns that the supply chain attack could expose sensitive user data and compromise the security of individual Chrome users.

3

Which Chrome extensions are specifically mentioned as affected by the attack?

The affected Chrome extensions mentioned include the Reader Mode extension versions 1.5.7 and 1.5.9.

4

What software besides Chrome extensions was noted to be impacted?

The Cyberhaven data protection tool is also mentioned as being potentially affected by the supply chain attack.

5

How can users protect themselves from this type of supply chain attack?

Users are advised to regularly update their extensions and be cautious when installing or enabling extensions from unverified developers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Supply chain attack hits Chrome extensions, could expose millions - SecAlerts