Hackers injected malicious code into several Chrome extensions in recent attack

Hackers were reportedly able to modify several Chrome extensions with malicious code this month after gaining access to admin accounts through a phishing campaign. The cybersecurity company Cyberhaven shared in a blog post this weekend that its Chrome extension was compromised on December 24 in an attack that appeared to be “targeting logins to specific social media advertising and AI platforms.” A few other extensions were hit as well, going back to mid-December, Reuters reported. According to Nudge Security’s Jaime Blasco, that includes ParrotTalks, Uvoice and VPNCity.

Cyberhaven notified its customers on December 26 in an email seen by TechCrunch, which advised them to revoke and rotate their passwords and other credentials. The company’s initial investigation of the incident found that the malicious extension targeted Facebook Ads users, with a goal of stealing data such as access tokens, user IDs and other account information, along with cookies. The code also added a mouse click listener. “After successfully sending all the data to the [Command & Control] server, the Facebook user ID is saved to browser storage,” Cyberhaven said in its analysis. “That user ID is then used in mouse click events to help attackers with 2FA on their side if that was needed.”

Cyberhaven said it first detected the breach on December 25 and was able to remove the malicious version of the extension within an hour. It’s since pushed out a clean version.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/hackers-injected-malicious-code-into-several-chrome-extensions-in-recent-attack-220648155.html?src=rss https://www.engadget.com/cybersecurity/hackers-injected-malicious-code-into-several-chrome-extensions-in-recent-attack-220648155.html?src=rss
Établi 7d | 29 déc. 2024 à 23:10:11


Connectez-vous pour ajouter un commentaire

Autres messages de ce groupe

LG's OLED evo TVs for 2025 come with AI and a 165Hz refresh rate

LG has unveiled its OLED evo TV lineup for 2025 and is showing them off at CES this year, along with its other

5 janv. 2025 à 22:11:09 | Engadget
The second-gen Kindle Scribe is on sale for the first time

If you’ve been waiting for the right moment to upgrade your Kindle Scribe, now wouldn’t be a bad time — Amazon is running its first sale on the new model, which has only been out for a month. Norma

5 janv. 2025 à 19:51:05 | Engadget
LG previews the compact S20A soundbar at CES 2025

LG is carrying over much of its 2024 sou

5 janv. 2025 à 19:51:04 | Engadget
Belkin’s new Creator Bundle makes hands-free recording easy

Belkin just unveiled a unique bundle at CES 2025 that’s being described as a “comprehensive toolset designed to meet the needs of budding creators.” The appropriately-named Creator Bundle comes wit

5 janv. 2025 à 17:30:15 | Engadget
Roborock's new flagship robot vacuum has an arm that can grab small objects

Robot vacuums can remove the dust and dirt on your floor, but you still have to pick up stray socks and and any item strewn about your home. Now

5 janv. 2025 à 17:30:14 | Engadget
Belkin’s new accessory is a magnetic power bank and camera grip rolled into one

Belkin has a new phone accessory at CES 2025 that somehow brings something fresh to the crowded field of magnetic charg

5 janv. 2025 à 17:30:13 | Engadget
United will start testing Starlink on flights in February

United Airlines has announced plans to start testing Starlink on flights in February, and eventually add SpaceX's satellite internet service to its entire fleet. The company first announced

5 janv. 2025 à 15:10:18 | Engadget