Cyber Security News

New Supply Chain Attack Targeting Chrome Extensions To Inject Malicious Code

A sophisticated supply chain attack targeting Chrome browser extensions has compromised at least 35 Chrome extensions, potentially exposing over 2.6 million users to data theft and credential harvesting.

The campaign, which began in mid-December 2024, exploited extension developers through a targeted phishing operation, allowing threat actors to inject malicious code into legitimate extensions.

The attack chain started with phishing emails sent to Chrome extension developers, impersonating Google Chrome Web Store support.

Phishing email claiming a fake violation related to a Chrome extension (Source – Sekoia)

These emails claimed that the developer’s extension violated store policies and was at risk of removal.

Malicious OAuth application “Privacy Policy Extension” requesting access to update the Chrome Web Store extensions (Source – Sekoia)

Security experts at Sekoia noted that clicking the embedded link led victims to a legitimate Google OAuth authorization page for a malicious application named “Privacy Policy Extension.”

Once authorized, the threat actors gained full access to publish new versions of the targeted extensions.

They then uploaded modified versions containing two malicious JavaScript files: background.js and context_responder.js. These scripts communicate with command and control (C2) servers to download configurations and exfiltrate sensitive user data.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Supply Chain Attack & Adversary’s Infrastructure

The injected code primarily targeted Facebook Business users, harvesting API keys, session cookies, access tokens, account information, and ad account details. Additionally, some variants attempted to steal OpenAI ChatGPT API keys and user authentication data.

Supply chain attack and the adversary’s infrastructure (Source – Sekoia)

Cybersecurity firm Cyberhaven was among the first to detect the compromise on December 26, 2024. Their investigation revealed that the attacker’s infrastructure had been active since at least March 2024, suggesting earlier campaigns may have gone unnoticed.

Notable compromised extensions include:-

  • GraphQL Network Inspector
  • Proxy SwitchyOmega (V3)
  • YesCaptcha assistant
  • Castorus
  • VidHelper – Video Download Helper
  • Internxt VPN
  • Vidnoz Flex
  • Wayin AI
  • Reader Mode
  • Primus (prev. PADO)
  • TinaMind
  • VPNCity
  • Uvoice
  • ParrotTalks
  • Bookmark Favicon Changer
  • Cyberhaven

The threat actors utilized a network of domains for C2 communication, with many resolving to two IP addresses: 149.28.124[.]84 and 45.76.225[.]148. They also employed 149.248.2[.]160 for data exfiltration.

To identify potential compromise, users can check their Chrome local storage for keys like “graphqlnetwork_ext_manage” or similar extension-specific keys containing downloaded configurations.

Attacker websites impersonating AI and Ads Block solutions (Source – Sekoia)

As a result of this, organizations should carefully review their policies on browser extension usage and implement strict controls to mitigate potential threats.

Recommended actions for users:-

  1. Remove or update affected extensions to versions released after December 26, 2024.
  2. Reset important account passwords, especially for Facebook and ChatGPT.
  3. Clear browser data and reset settings to defaults.
  4. Monitor account activity for any suspicious behavior.

For extension developers:-

  1. Implement robust multi-factor authentication for developer accounts.
  2. Carefully review all OAuth application access requests.
  3. Regularly audit extension code for unauthorized changes.

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago