2024 Cyberhaven — Chrome Web Store account takeover; malicious extension build (supply chain)
Data compromised
Browser cookies, authentication/session tokens, and related client metadata per incident analyses—exact exfiltration varied by victim
Technical writeup
Over the 2024 Christmas Eve window, Cyberhaven publicly confirmed threat actors compromised an employee account via a phishing campaign framed as Chrome Web Store developer support, then abused publishing access to ship a trojaned build of Cyberhaven’s Chrome browser extension (reported as version 24.10.4 in industry write-ups). Analysts and Cyberhaven stated the malicious package could harvest browser-session material (e.g., cookies, tokens, user-agent context) with observed targeting narratives around high-value accounts such as advertising platforms. Cyberhaven described rapid detection on December 25, 2024, takedown of the rogue listing, release of a clean build, and coordination with law enforcement; press and vendors situated the incident inside a broader wave of Chrome-extension developer account hijacks affecting many publishers and millions of cumulative installs.
Root cause
Credential phishing against workforce leading to Chrome Web Store developer account takeover; malicious extension update publication
References
- https://www.reuters.com/technology/cybersecurity/data-loss-prevention-company-cyberhaven-hit-by-breach-statement-says-2024-12-27/
- https://www.darktrace.com/blog/cyberhaven-supply-chain-attack-exploiting-browser-extensions
- https://www.nightfall.ai/blog/heres-what-we-can-learn-from-the-cyberhaven-incident