The Cyberhaven Chrome Extension Supply Chain Attack

Updated 5 Oct 2026 · Incident date 25 Dec 2024 · browser extension

PackageCyberhaven Chrome extension 24.10.3 -> 24.10.4 (part of a campaign hitting 35+ extensions)
Fileworker.js

Cyberhaven Chrome extension version 24.10.4 carried code that sent cookies and sessions to an attacker domain. A phishing attack on 24 December 2024 gave the attacker access to the company's Chrome Web Store account. Version 24.10.5 is the fixed release.

The attack was part of a wider campaign against Chrome extension developers.

What happened

A phishing attack let an attacker publish a bad update of the Cyberhaven extension to the Chrome Web Store. SOCRadar reports that the email went to a public support address. It led to a malicious OAuth app named "Privacy Policy Extension". The attack worked even though multi-factor authentication and Google Advanced Protection were on. The reason given is that OAuth consent is an authorization step, and multi-factor authentication protects sign-in.

BleepingComputer reports that the injected code could send authenticated sessions and cookies to the attacker domain cyberhavenext[.]pro. The company found the breach on 24 December, removed the code within one hour of detection and published 24.10.5 on 26 December 2024.

SOCRadar describes the changed files. In worker.js, the code connected to a command server, downloaded a configuration and registered listeners for web requests. A second file, content.js, took data from Facebook users. It targeted Facebook access tokens, account details, cookies and user-agent strings. It also watched mouse clicks to detect QR codes.

The extension is a data-loss-prevention product, so its service worker already made network requests and read browser data. The change that matters is that the new code took its instructions from a configuration that a stranger's server supplied.

Sekoia ties the attack to a wider campaign. It reports that other extensions were compromised between 12 and 30 December 2024, using phishing emails that pretended to come from the Chrome Web Store and claimed a policy violation. BleepingComputer reports at least 18 other extensions with similar code, with about 380,000 users together.

Affected versions

Indicators of compromise

How to check

Open chrome://extensions and read the Cyberhaven version. You can also search the extension files on disk for the attacker domain. This command works on macOS. On Linux, use ~/.config/google-chrome instead.

grep -rl "cyberhavenext" ~/Library/Application\ Support/Google/Chrome/*/Extensions/ 2>/dev/null

A match means a profile holds the bad build. Also search DNS and proxy logs for cyberhavenext.pro.

What to do now

  1. Update the extension to 24.10.5 or later.
  2. Revoke sessions and rotate passwords for sites that you used in the browser during the window, including Facebook and AI platform accounts.
  3. Rotate API tokens. BleepingComputer advises revoking passwords that are not protected by FIDO2 keys.
  4. Review browser and network logs for traffic to cyberhavenext.pro.
  5. If you publish an extension, review OAuth apps that request access to your store account before you approve them.
  6. Vigilance compares a new extension build with the one you trust and reports the file that gained a new capability. Here, worker.js changed in an extension that already made outbound requests, so the change is new configuration-driven behavior and not a clearly new capability.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old extension-24.10.3 --new extension-24.10.4
files scanned: 72 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   worker.js
           It restarts itself after a reboot and reads your personal files.

Frequently asked questions

Which Cyberhaven extension version was compromised?

Version 24.10.4 of the Cyberhaven Chrome extension. Version 24.10.5, released on 26 December 2024, is the fixed release.

How was the Cyberhaven Chrome extension compromised?

A phishing email led an employee to approve a malicious OAuth app named Privacy Policy Extension, which gave the attacker access to the Chrome Web Store account.

What did the compromised Cyberhaven extension steal?

It could send authenticated sessions and cookies to cyberhavenext[.]pro. SOCRadar says the code targeted Facebook access tokens, account details and cookies.

How do I check if I had the compromised Cyberhaven extension?

Check chrome://extensions for version 24.10.4 and search your extension files and network logs for cyberhavenext.pro.

Sources

  1. socradar.io/blog/phishing-attack-cyberhaven-chrome-extension/
  2. bleepingcomputer.com/news/security/cybersecurity-firms-chrome-extension-hijacked-to-steal-users-data/
  3. sekoia.com/blog/targeted-supply-chain-attack-against-chrome-browser-extensions

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free