Cybersecurity outfit Sekoia is warning Chrome users of a supply chain attack targeting browser extension developers that has potentially impacted hundreds of thousands of individuals already. Dozens of Chrome extension developers have fallen victim to the attacks thus far, which aimed to lift API keys, session cookies, and other authentication tokens from websites such as ChatGPT and Facebook for Business. Sekoia examined the infrastructure used for the wide-scale phishing campaign targeting devs and traced it back to similar attacks as far back as 2023 with "high confidence." The latest known campaign activity occurred on December 30, 2024, however. Among the victims was California-based Cyberhaven, which makes a cloud-based data protection tool. The company was one of the unfortunate ones to detect the compromise over the holiday period on Boxing Day 2024 – a discovery that was widely reported at the time. Booz Allen Hamilton analyzed the incident at Cyberhaven and backed up the vendor's suspicions that it was part of a wider campaign. Its accompanying report [PDF] to the Cyberhaven analysis revealed a long list of other extensions it believes were likely affected, taking the potential number of affected end users into the millions. Sekoia published a less comprehensive list in its research, although the same extensions appear on both lists. A number of the potentially affected extensions (according to Booz Allen Hamilton's report) appear to have been pulled from the Chrome...
Supply chain attack hits Chrome extensions, could expose millions
The Register
·Connor Jones
·Published Jan 22, 2025
·Updated
Affected Software
4 affected components
Reader Mode extension=1.5.7
Reader Mode extension=1.5.9
Google Chrome
Cyberhaven data protection tool
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a supply chain attack that has impacted Chrome extensions, potentially affecting hundreds of thousands of users.
2
What security implications are discussed in the article?
The article warns that the supply chain attack could expose sensitive user data and compromise the security of individual Chrome users.
3
Which Chrome extensions are specifically mentioned as affected by the attack?
The affected Chrome extensions mentioned include the Reader Mode extension versions 1.5.7 and 1.5.9.
4
What software besides Chrome extensions was noted to be impacted?
The Cyberhaven data protection tool is also mentioned as being potentially affected by the supply chain attack.
5
How can users protect themselves from this type of supply chain attack?
Users are advised to regularly update their extensions and be cautious when installing or enabling extensions from unverified developers.