Supply Chain Attack on Chrome Browser Extensions

Red | Vulnerability Report
Download PDF

A recent supply chain attack compromised over a dozen Chrome browser extensions, impacting hundreds of thousands of users. The attackers used phishing campaigns to target developers, gaining access via a malicious OAuth application to publish malware-laden updates. The malicious code harvested sensitive data, including API keys, session cookies, and credentials from services like ChatGPT and Facebook for Business. This campaign highlights the growing risk of supply chain attacks and the need for stronger security measures for developers and users alike.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox