Google Chrome extensions targeted by hackers to steal user passwords

Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
(Image credit: Shutterstock)

  • Christmas Eve attack sees Cyberhaven Chrome extension hit
  • Some data could have been exfiltrated, Cyberhaven systems secure
  • Users are being told to change their passwords

Cyberhaven has confirmed its Google Chrome extension was the subject of a Christmas Eve cyberattack, exposing sensitive customer data like passwords and session tokens.

In a statement, the data loss prevention company noted the attack showed signs of being part of a “wider campaign” to target other companies, too.

The attack started as many others do – an employee fell for a phishing email and shared their credentials, giving the threat actor access to Cyberhaven’s systems.

Cyberhaven shares details of Christmas Eve attack

More specifically, the attacker obtained the worker’s Google Chrome Web Store credentials, allowing them to post a malicious version of its Chrome extension to the marketplace. Only version 24.10.4 was affected on Chrome-based browsers that auto-updated; the code was active between 1:32 AM UTC on December 25 and 2:50 AM UTC on December 26.

CEO Howard Ting said the compromise was detected by the firm’s security team at 11:54 PM UTC on Christmas Day – it was removed within an hour, noting, “I’m proud of how quickly our team reacted, with virtually everyone in the company interrupting their holiday plans to serve our customers, and acting with the transparency that is core to our company values.”

No other Cyberhaven systems, such as CI/CD processes and code signing keys, were compromised, however users’ cookies and authenticated sessions for certain targeted websites could have been exfiltrated.

Users are now being advised to maintain basic internet hygiene principles, such as ensuring that their extensions are up to date (in this case, version 24.10.5 or newer), reviewing logs for suspicious activity, and revoking or rotating all passwords that aren't FIDOv2.

The company has already implemented additional security measures to prevent similar future attacks and is actively cooperating with law enforcement.

You might also like

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Chrome icon on Android
Google Chrome extensions hack may have started much earlier than expected
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Data leak
AWS customers hit by major cyberattack which then stored stolen credentials in plain sight
Latest in Security
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
An American flag flying outside the US Capitol building against a blue sky
Mass federal layoffs will have “devastating impact on cybersecurity, former NSA cybersecurity director warns
A hand reaching out to touch a futuristic rendering of an AI processor.
North Korean fake job hackers are going the extra mile to make sure their scams seem legit
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
Latest in News
Stock photographs of people smiling and looking at laptops in a small business environment.
This web hosting platform elevates your online presence
The Samsung Galaxy S25 Edge on display at Galaxy Unpacked
Exclusive: the Samsung Galaxy S25 Edge will have durability to match its ‘sexy’ form
Metaphor: ReFantazio
Sega was Metacritic's highest-rated publisher of 2024 thanks to the critically acclaimed Metaphor: ReFantazio and Like a Dragon: Infinite Wealth
AirPods Pro Review
Apple has quietly updated its guidance on how to clean your AirPods, and suggests you buy a kit… from Belkin
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
A screen shot of Lady Gaga in her interview with Zane Lowe for Apple Music
Lady Gaga’s Spotify press conference is being live streamed today – here’s where you can watch Spotify’s big step forward in fan inclusion