Chrome in danger: hackers managed to inject malicious code into extensions of the popular browser

A cyber attacker has managed to install malicious modifications of legitimate extensions for the Chrome browser in a ‘phishing’ campaign deployed at Christmas, which has affected the security firm Cyberhaven.

Cyberhaven is a cybersecurity company that has developed an extension for Chrome to strengthen the security of users while using this browser, which, however, due to a malicious campaign, has spread an insecure modified version for a few hours.

It is due to the ‘phishing’ campaign that allowed a cyber attacker to activate malicious code in the legitimate extension at Christmas, which has put users of the browser version that had automatic updating activated at risk.

In their case, a phishing attack managed to obtain the access credentials to the Chrome extension store from a Cyberhaven employee, which facilitated the publication of the malicious extension (v24.10.4).

The Cyberhaven security team detected the change and “removed the malicious package in 60 minutes,” it confirmed on its official blog, where it explains the situation. They then notified users, starting with those affected, of the incident, and They published an updated version free of malicious code (v24.10.5).

Cyberhaven has not been the only one affected by the ‘phishing’ campaign, as can be seen from the investigation they have initiated. “Our initial findings show that the attacker targeted logins to specific AI and social media advertising platforms.“, they point out.

Nudge Security co-founder and CTO Jaime Blasco also believes there are more extensions affected, judging by his IP address analysis. “There are more domains created within the same time interval that resolve to the same IP address” than that of the malicious Cyberhaven extension.

In fact, Blasco cites that the ParrotTalks, Uvoice and VPNCity extensions are among those affected, as reported on the social network X (formerly Twitter).

By Editor

One thought on “Chrome in danger: hackers managed to inject malicious code into extensions of the popular browser”
  1. 안전한 토토사이트 추천 및 이용 가이드 – Style Flavors
    최고 인기 온라인 스포츠 베팅 사이트 순위 안내 – 온라인 스포츠 베팅 순위
    Home – Soul Full Veda
    축구 규칙과 심판 규정 설명서 – 기본적인 이해 – 축구 규칙 가이드
    Home – BB BORGO PONTE
    Home – Georgian Women
    Home – Korea Expert Witness
    Home – Hotel Hanseat
    Krikya Live Casino: The Ultimate Interactive Experience | Loyal Shayar
    집 – 예쁜 안마
    Home – Renew My Health
    Home – Gwangyang Buddy
    다양한 카지노게임: 즐거움과 스릴을 한 번에! – Cambodias Wildlife
    Home – Bubu Land
    농구 경기 규칙 완벽 가이드: 게임의 이해를 위한 핵심 – 농구 규칙 설명
    Home – Trengle
    Home – DTForum
    최고의 축구 게임 추천! 연령별 인기 선택 – Diagnostic Engineers
    Home – Reflexologie Lenka
    카지노 베팅 전략 – 승리 확률 높이는 방법 – 카지노 배팅 방법
    스포츠 베팅 마스터하기: 효율적인 배팅 방법 전략 – 올바른 베팅전략
    집 – 경희 몸매 예쁘다
    Home – Go Sports Toto
    안전 토토사이트 선택하는 비결과 이용방법 – Cherry Works
    Home – Gary Primich
    Home – Healthy Waco Women
    검증된 바카라 배팅 전략 – 승률 높이는 비법 – 유효한 배팅 시스템
    토토사이드 순위 검증 통한 메이저사이트 선택 가이드 5선 제시 및 사설 토토사이트 추천 – hankstruckpictures
    오늘의 주요 스포츠 경기 일정 – 전체 리뷰 및 하이라이트 – 스포츠 경기 리스트
    성공으로 이끄는 스포츠 베팅 꿀팁 대공개 – Blaine Recovery

Leave a Reply