Cyberhaven said attackers compromised its Google Chrome extension publishing process and pushed a malicious update that could steal credentials and other sensitive browser data from affected users. Reporting indicates the trojanized extension targeted logged-in sessions and authentication material, with the incident drawing attention because Cyberhaven is itself a cybersecurity company. The compromise affected the company's browser extension distributed through the Chrome Web Store, turning a trusted security tool into a delivery mechanism for data theft.
Follow-up reporting and incident write-ups said the malicious version was removed and replaced after discovery, while customers were urged to identify impacted endpoints, revoke exposed credentials, rotate passwords, and review browser activity for signs of session or token theft. The case highlights a software supply-chain style attack against browser extensions, where attackers abused a vendor's update channel to distribute malware under the guise of a legitimate signed release.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Security reporting said the same operation had compromised at least 35 Chrome extensions affecting roughly 2.6 million users. The reports also described a fake Chrome Web Store policy email lure that tricked developers into authorizing a malicious OAuth app, enabling attackers to publish tampered extensions aimed at stealing Facebook-related tokens and account data.
Cyberhaven publicly confirmed that its Chrome extension had been compromised and advised customers to rotate passwords, revoke tokens, and review logs for suspicious activity. Security reporting also highlighted that the campaign may have affected other Chrome extensions through similar publisher-account compromises.
Cyberhaven identified the unauthorized extension update, revoked the attacker's access, and removed the malicious version from distribution. The company began incident response and notified customers about the compromise.
Using the compromised publisher account, the attacker published a malicious version of Cyberhaven's Chrome extension that was designed to exfiltrate sensitive data, including authenticated sessions and credentials from affected users. Reporting indicates the malicious update was available through the Chrome Web Store before it was detected and removed.
Cyberhaven said the incident began when a threat actor successfully phished an employee and used the stolen credentials to access the company's Chrome Web Store publisher account. This access enabled the attacker to tamper with the Cyberhaven browser extension release process.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcecodeby.net
Open sourcecodeby.net
Open sourcebleepingcomputer.com
Open sourcesecureannex.com
Open sourcetechcrunch.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.