Hackers injected malicious code into several Chrome extensions in recent attack

You May Be Interested In:AMC Theatres will screen a Swedish movie ‘visually dubbed’ with the help of AI


Hackers were reportedly able to modify several Chrome extensions with malicious code this month after gaining access to admin accounts through a phishing campaign. The cybersecurity company Cyberhaven shared in a this weekend that its Chrome extension was compromised on December 24 in an attack that appeared to be “targeting logins to specific social media advertising and AI platforms.” A few other extensions were hit as well, going back to mid-December, reported. According to Nudge Security’s , that includes ParrotTalks, Uvoice and VPNCity.

Cyberhaven notified its customers on December 26 in an email seen by , which advised them to revoke and rotate their passwords and other credentials. The company’s initial investigation of the incident found that the malicious extension targeted Facebook Ads users, with a goal of stealing data such as access tokens, user IDs and other account information, along with cookies. The code also added a mouse click listener. “After successfully sending all the data to the [Command & Control] server, the Facebook user ID is saved to browser storage,” Cyberhaven said in its analysis. “That user ID is then used in mouse click events to help attackers with 2FA on their side if that was needed.”

Cyberhaven said it first detected the breach on December 25 and was able to remove the malicious version of the extension within an hour. It’s since pushed out a clean version.

share Paylaş facebook pinterest whatsapp x print

Similar Content

Austrian activist Schrems wins privacy case against Meta over personal data on sexual orientation
Austrian activist Schrems wins privacy case against Meta over personal data on sexual orientation
Opinion: The TikTok court case has staggering implications for free speech in America
Opinion: The TikTok court case has staggering implications for free speech in America
Health care CEOs: Artificial intelligence is a 'game changer'
Health care CEOs: Artificial intelligence is a 'game changer'
Appeals court orders new trial for man on Texas' death row over judge's antisemitic bias
Appeals court orders new trial for man on Texas’ death row over judge’s antisemitic bias
Tech consultant spars with the prosecutor over details of the death of Cash App founder Bob Lee
Tech consultant spars with the prosecutor over details of the death of Cash App founder Bob Lee
Hulu Black Friday streaming deals discount one year of the Disney+ Hulu bundle to only $36
Hulu Black Friday streaming deals discount one year of the Disney+ Hulu bundle to only $36
The Daily Lens | © 2024 | News