Hackers hijacked several Chrome extensions, injecting malicious code aimed at stealing user data like web browser cookies, particularly targeting advertising accounts and AI platform credentials.
Cyberhaven, who discovered the breach, reported that the cyberattack involved pushing an updated malicious version of their Chrome extension to users, starting Christmas Eve.
The attack was triggered when a Cyberhaven employee fell victim to a phishing email disguised as an official Google contact, leading to stolen login credentials.
Other affected Chrome extensions, including Internxt VPN and VPNCity, cater to large user bases, raising concerns about the potential impact on user security.
Collection
[
|
...
]