The Cyberhaven Chrome Extension Supply Chain Attack
Updated 5 Oct 2026 · Incident date 25 Dec 2024 · browser extension
Cyberhaven Chrome extension 24.10.3 -> 24.10.4 (part of a campaign hitting 35+ extensions)worker.jsCyberhaven Chrome extension version 24.10.4 carried code that sent cookies and sessions to an attacker domain. A phishing attack on 24 December 2024 gave the attacker access to the company's Chrome Web Store account. Version 24.10.5 is the fixed release.
The attack was part of a wider campaign against Chrome extension developers.
What happened
A phishing attack let an attacker publish a bad update of the Cyberhaven extension to the Chrome Web Store. SOCRadar reports that the email went to a public support address. It led to a malicious OAuth app named "Privacy Policy Extension". The attack worked even though multi-factor authentication and Google Advanced Protection were on. The reason given is that OAuth consent is an authorization step, and multi-factor authentication protects sign-in.
BleepingComputer reports that the injected code could send authenticated sessions and cookies to the attacker domain cyberhavenext[.]pro. The company found the breach on 24 December, removed the code within one hour of detection and published 24.10.5 on 26 December 2024.
SOCRadar describes the changed files. In worker.js, the code connected to a command server, downloaded a configuration and registered listeners for web requests. A second file, content.js, took data from Facebook users. It targeted Facebook access tokens, account details, cookies and user-agent strings. It also watched mouse clicks to detect QR codes.
The extension is a data-loss-prevention product, so its service worker already made network requests and read browser data. The change that matters is that the new code took its instructions from a configuration that a stranger's server supplied.
Sekoia ties the attack to a wider campaign. It reports that other extensions were compromised between 12 and 30 December 2024, using phishing emails that pretended to come from the Chrome Web Store and claimed a policy violation. BleepingComputer reports at least 18 other extensions with similar code, with about 380,000 users together.
Affected versions
- Cyberhaven Chrome extension 24.10.4. The last clean version before it is 24.10.3.
- Fixed in 24.10.5, released on 26 December 2024.
- The company removed the malicious code within one hour of detection. The sources above do not give the exact hours of exposure.
Indicators of compromise
- Domain that received stolen data:
cyberhavenext[.]pro. - Phishing OAuth app name: "Privacy Policy Extension". Sekoia lists the name for other extensions as "Privacy Policy Extensions".
- Sekoia lists phishing domains
app.checkpolicy[.]site,chromeforextension[.]comandsupportchromestore[.]com. - Changed extension files:
worker.jsandcontent.js. - Extension version 24.10.4.
How to check
Open chrome://extensions and read the Cyberhaven version. You can also search the extension files on disk for the attacker domain. This command works on macOS. On Linux, use ~/.config/google-chrome instead.
grep -rl "cyberhavenext" ~/Library/Application\ Support/Google/Chrome/*/Extensions/ 2>/dev/null
A match means a profile holds the bad build. Also search DNS and proxy logs for cyberhavenext.pro.
What to do now
- Update the extension to 24.10.5 or later.
- Revoke sessions and rotate passwords for sites that you used in the browser during the window, including Facebook and AI platform accounts.
- Rotate API tokens. BleepingComputer advises revoking passwords that are not protected by FIDO2 keys.
- Review browser and network logs for traffic to
cyberhavenext.pro. - If you publish an extension, review OAuth apps that request access to your store account before you approve them.
- Vigilance compares a new extension build with the one you trust and reports the file that gained a new capability. Here,
worker.jschanged in an extension that already made outbound requests, so the change is new configuration-driven behavior and not a clearly new capability.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 72 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE worker.js It restarts itself after a reboot and reads your personal files.
Frequently asked questions
Which Cyberhaven extension version was compromised?
Version 24.10.4 of the Cyberhaven Chrome extension. Version 24.10.5, released on 26 December 2024, is the fixed release.
How was the Cyberhaven Chrome extension compromised?
A phishing email led an employee to approve a malicious OAuth app named Privacy Policy Extension, which gave the attacker access to the Chrome Web Store account.
What did the compromised Cyberhaven extension steal?
It could send authenticated sessions and cookies to cyberhavenext[.]pro. SOCRadar says the code targeted Facebook access tokens, account details and cookies.
How do I check if I had the compromised Cyberhaven extension?
Check chrome://extensions for version 24.10.4 and search your extension files and network logs for cyberhavenext.pro.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.