Categories: GADGET

Hackers injected malicious code into several Chrome extensions in recent attack


Hackers were reportedly able to modify several Chrome extensions with malicious code this month after gaining access to admin accounts through a phishing campaign. The cybersecurity company Cyberhaven shared in a this weekend that its Chrome extension was compromised on December 24 in an attack that appeared to be “targeting logins to specific social media advertising and AI platforms.” A few other extensions were hit as well, going back to mid-December, reported. According to Nudge Security’s , that includes ParrotTalks, Uvoice and VPNCity.

Cyberhaven notified its customers on December 26 in an email seen by , which advised them to revoke and rotate their passwords and other credentials. The company’s initial investigation of the incident found that the malicious extension targeted Facebook Ads users, with a goal of stealing data such as access tokens, user IDs and other account information, along with cookies. The code also added a mouse click listener. “After successfully sending all the data to the [Command & Control] server, the Facebook user ID is saved to browser storage,” Cyberhaven said in its analysis. “That user ID is then used in mouse click events to help attackers with 2FA on their side if that was needed.”

Cyberhaven said it first detected the breach on December 25 and was able to remove the malicious version of the extension within an hour. It’s since pushed out a clean version.



Source link

fromermedia@gmail.com

Share
Published by
fromermedia@gmail.com

Recent Posts

How Does Rent To Own Work? (Who Should Do It & Major Risks)

Rent-to-own combines renting with the option to purchase a home later, but this arrangement carries…

2 mins ago

Bringing Down Grocery Prices, Trump Style

CPI food at home is 8% of total CPI weights, fresh vegetables and fruit are…

3 mins ago

Temu’s owner sheds billions in value over fears Trump’s trade crackdown will curb U.S. appetite for China-shipped goods

The elimination of the so-called de minimis trade rule could wreak havoc on Temu, Shein,…

5 mins ago

US senator hints Trump’s latest EO could mean the US buying Bitcoin

Wyoming Senator Cynthia Lummis suggested Donald Trump’s executive order creating a US sovereign wealth fund…

6 mins ago

Nintendo Might Be Making Switch 2 Game Cases Absurdly Big

When Switch cases arrived back in 2017, they looked comically unnecessary. The SD cards the…

8 mins ago

Circa Squares Contest Returns for Super Bowl • This Week in Gambling

Just in time for your Super Bowl fun, the return of the Circa Squares contest…

8 mins ago