Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
extension-plugin-hijackvendor-distribution-compromisecredential-stealer-activityleaked-secret-api-key

Cyberhaven Chrome Extension Hijacked to Deliver Credential-Stealing Update

Updated 11h agoFirst seen May 25, 20264 sources

Cyberhaven said attackers compromised its Google Chrome extension publishing process and pushed a malicious update that could steal credentials and other sensitive browser data from affected users. Reporting indicates the trojanized extension targeted logged-in sessions and authentication material, with the incident drawing attention because Cyberhaven is itself a cybersecurity company. The compromise affected the company's browser extension distributed through the Chrome Web Store, turning a trusted security tool into a delivery mechanism for data theft.

Follow-up reporting and incident write-ups said the malicious version was removed and replaced after discovery, while customers were urged to identify impacted endpoints, revoke exposed credentials, rotate passwords, and review browser activity for signs of session or token theft. The case highlights a software supply-chain style attack against browser extensions, where attackers abused a vendor's update channel to distribute malware under the guise of a legitimate signed release.

Share:
Cyberhaven Chrome Extension Hijacked to Deliver Credential-Stealing Update
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Dec 31, 20241y ago

Reports link Cyberhaven incident to 35-extension hijacking campaign

Security reporting said the same operation had compromised at least 35 Chrome extensions affecting roughly 2.6 million users. The reports also described a fake Chrome Web Store policy email lure that tricked developers into authorizing a malicious OAuth app, enabling attackers to publish tampered extensions aimed at stealing Facebook-related tokens and account data.

New details reveal how hackers hijacked 35 Google Chrome extensions
Dec 27, 20242y ago

Cyberhaven discloses incident and publishes customer guidance

Cyberhaven publicly confirmed that its Chrome extension had been compromised and advised customers to rotate passwords, revoke tokens, and review logs for suspicious activity. Security reporting also highlighted that the campaign may have affected other Chrome extensions through similar publisher-account compromises.

Dec 25, 20242y ago

Cyberhaven detects compromise and removes malicious extension

Cyberhaven identified the unauthorized extension update, revoked the attacker's access, and removed the malicious version from distribution. The company began incident response and notified customers about the compromise.

Dec 24, 20242y ago

Malicious Cyberhaven Chrome extension update published

Using the compromised publisher account, the attacker published a malicious version of Cyberhaven's Chrome extension that was designed to exfiltrate sensitive data, including authenticated sessions and credentials from affected users. Reporting indicates the malicious update was available through the Chrome Web Store before it was detected and removed.

Threat actor compromises Cyberhaven employee account via phishing

Cyberhaven said the incident began when a threat actor successfully phished an employee and used the stolen credentials to access the company's Chrome Web Store publisher account. This access enabled the attacker to tamper with the Cyberhaven browser extension release process.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
1 linked
Facebook
Organizations
6 linked
CyberhavenGoogleBleepingComputerVirustotalMeta PlatformsLayerX
Breaches
1 linked
CYBERHAVEN-2024-12
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.