The December 2024 Chrome Extension Supply Chain Attack

Updated 5 Oct 2026 · Incident date 18 Dec 2024 · browser extension

Package~35 extensions incl. Reader Mode (malicious 1.5.7 and 1.5.9), Proxy SwitchyOmega V3, GraphQL Network Inspector, Internxt VPN, VPNCity, ParrotTalks, Uvoice
Filebackground.js and context_responder.js

In December 2024, attackers phished Chrome Web Store developers and used a fake OAuth app to publish malicious updates to more than 35 extensions. Reader Mode (version 1.5.7), Proxy SwitchyOmega V3, GraphQL Network Inspector, Internxt VPN, VPNCity, ParrotTalks and Uvoice were among them.

The Cyberhaven extension was the best known case. Its malicious version 24.10.4 was live for about a day, according to The Hacker News.

What happened

Attackers sent developers a fake Chrome Web Store policy warning and asked them to approve a malicious OAuth application. Sekoia reports that the app was named "Privacy Policy Extensions." Approval gave the attackers permission to see, edit, update and publish extensions in the developer's Web Store account. They then pushed new versions that held extra code.

The phishing mails came from look-alike domains, such as chromeforextension[.]com and supportchromestore[.]com. A Cyberhaven employee was targeted on 24 December 2024, and Cyberhaven disclosed the compromise a few days later.

Sekoia found two injected files in the extensions: background.js, which fetched a configuration from a command server, and context_responder.js, which ran in every page before other scripts. The code harvested cookies, access tokens and API keys. Sekoia names ChatGPT and Facebook for Business data. The Hacker News adds that the code searched Facebook pages for QR codes that help bypass two-factor sign-in.

Scale differs by source. The Hacker News reports more than 2.6 million users exposed across 35 or more extensions. RH-ISAC reports about 400,000 users for Cyberhaven alone and at least 16 extensions in the first set.

Vigilance compares the version you trust with the new one. These updates gained new scripts and permissions to run in every page. Vigilance reports the file that gained a new capability. See the scan block below.

Affected versions

Sekoia lists 16 extensions with the date of compromise. The full campaign includes about 35. Version numbers are in the sources only for some of them.

ExtensionIDCompromisedCommand domain
Proxy SwitchyOmega (V3)hihblcmlaaademjlakdpicchbjnnnkbo30 Dec 2024proxyswitchyomega[.]pro
GraphQL Network Inspectorndlbedplllcgconngcnfmkadhokfaaln29 Dec 2024graphqlnetwork[.]pro
YesCaptcha assistantjiofmdifioeejeilfkpegipdjiopiekl29 Dec 2024yescaptcha[.]pro
Castorusmnhffkhmpnefgklngfmlndmkimimbphc26 Dec 2024castorus[.]info
Uvoiceoaikpkmjciadfpddlpjjdapglcihgdle26 Dec 2024uvoice[.]live
VidHelper - Video Download Helperegmennebgadmncfjafcemlecimkepcle26 Dec 2024videodownloadhelper[.]pro
ParrotTalkskkodiihpgodmdankclfibbiphjkfdenh25 Dec 2024parrottalks[.]info
Bookmark Favicon Changeracmfnomgphggonodopogfbmkneepfgnh25 Dec 2024bookmarkfc[.]info
Internxt VPNdpggmcodlahmljkhlmpgpdcffdaoccni25 Dec 2024internxtvpn[.]pro
Vidnoz Flexcplhlgabfijoiabgkigdafklbhhdkahj25 Dec 2024vidnozflex[.]live
Cyberhavenpajkjnmeojmbapicmbpliphjmcekeaac24 Dec 2024cyberhavenext[.]pro
Wayin AIcedgndijpacnfbdggppddacngjfdkaca19 Dec 2024wayinai[.]live
Reader Modellimhhconnjiflfimocjggfjdlmlhblm18 Dec 2024readermodeext[.]info
Primus (previously PADO)oeiomhmbaapihbilkfkhmlajkeegnjhe18 Dec 2024primusext[.]pro
TinaMindbefflofjcniongenjmbkgkoljhgliihe15 Dec 2024tinamind[.]info
VPNCitynnpnnpemnckcfdebeekibpiijlicmpom12 Dec 2024vpncity[.]live

Reader Mode 1.5.7 is named as a compromised version by RH-ISAC. RH-ISAC also names Visual Effects for Google Meet 3.1.3, Email Hunter 1.4.4 and YesCaptcha Assistant 1.1.61. Cyberhaven version 24.10.4 was malicious. Version 24.10.5 is the clean release.

Indicators of compromise

How to check

Look for the extension IDs in your browser profiles. On macOS:

ls ~/Library/Application\ Support/Google/Chrome/*/Extensions | grep -E "hihblcmlaaademjlakdpicchbjnnnkbo|ndlbedplllcgconngcnfmkadhokfaaln|llimhhconnjiflfimocjggfjdlmlhblm|dpggmcodlahmljkhlmpgpdcffdaoccni|pajkjnmeojmbapicmbpliphjmcekeaac|nnpnnpemnckcfdebeekibpiijlicmpom"

This checks six of the IDs in the table. Add the rest to the pattern. Then search proxy and DNS logs for the command domains above. If you publish an extension, review the OAuth apps that can access your Web Store developer account.

What to do now

  1. Update or remove every extension in the table. Use only a version released after the clean fix.
  2. Revoke API keys, session tokens and passwords that those browsers held, for example OpenAI and Facebook credentials.
  3. Block the domains and IP addresses above.
  4. Developers: remove the "Privacy Policy Extension" OAuth app, change your password and enable strong two-factor sign-in.
  5. Remember that Chrome Web Store messages come from the Chrome developer dashboard. Do not use links in a policy-warning email.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old package-prev --new package-current
files scanned: 23 (2 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   background.js
           It downloads from the internet and reads saved passwords and access keys.

Frequently asked questions

Which Chrome extensions were compromised in December 2024?

More than 35 extensions were hit. Examples are Cyberhaven, Reader Mode, Proxy SwitchyOmega V3, GraphQL Network Inspector, Internxt VPN, VPNCity, ParrotTalks and Uvoice.

How did attackers get into the Chrome Web Store developer accounts?

They sent phishing emails that looked like Chrome Web Store policy warnings. The link asked developers to approve a malicious OAuth app that can publish extension updates.

Sources

  1. sekoia.com/blog/targeted-supply-chain-attack-against-chrome-browser-extensions
  2. thehackernews.com/2024/12/16-chrome-extensions-hacked-exposing.html
  3. rhisac.org/threat-intelligence/cyberhaven-extension-compromise-part-of-broader-campaign-affecting-multiple-chrome-extensions/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free