The December 2024 Chrome Extension Supply Chain Attack
Updated 5 Oct 2026 · Incident date 18 Dec 2024 · browser extension
~35 extensions incl. Reader Mode (malicious 1.5.7 and 1.5.9), Proxy SwitchyOmega V3, GraphQL Network Inspector, Internxt VPN, VPNCity, ParrotTalks, Uvoicebackground.js and context_responder.jsIn December 2024, attackers phished Chrome Web Store developers and used a fake OAuth app to publish malicious updates to more than 35 extensions. Reader Mode (version 1.5.7), Proxy SwitchyOmega V3, GraphQL Network Inspector, Internxt VPN, VPNCity, ParrotTalks and Uvoice were among them.
The Cyberhaven extension was the best known case. Its malicious version 24.10.4 was live for about a day, according to The Hacker News.
What happened
Attackers sent developers a fake Chrome Web Store policy warning and asked them to approve a malicious OAuth application. Sekoia reports that the app was named "Privacy Policy Extensions." Approval gave the attackers permission to see, edit, update and publish extensions in the developer's Web Store account. They then pushed new versions that held extra code.
The phishing mails came from look-alike domains, such as chromeforextension[.]com and supportchromestore[.]com. A Cyberhaven employee was targeted on 24 December 2024, and Cyberhaven disclosed the compromise a few days later.
Sekoia found two injected files in the extensions: background.js, which fetched a configuration from a command server, and context_responder.js, which ran in every page before other scripts. The code harvested cookies, access tokens and API keys. Sekoia names ChatGPT and Facebook for Business data. The Hacker News adds that the code searched Facebook pages for QR codes that help bypass two-factor sign-in.
Scale differs by source. The Hacker News reports more than 2.6 million users exposed across 35 or more extensions. RH-ISAC reports about 400,000 users for Cyberhaven alone and at least 16 extensions in the first set.
Vigilance compares the version you trust with the new one. These updates gained new scripts and permissions to run in every page. Vigilance reports the file that gained a new capability. See the scan block below.
Affected versions
Sekoia lists 16 extensions with the date of compromise. The full campaign includes about 35. Version numbers are in the sources only for some of them.
| Extension | ID | Compromised | Command domain |
|---|---|---|---|
| Proxy SwitchyOmega (V3) | hihblcmlaaademjlakdpicchbjnnnkbo | 30 Dec 2024 | proxyswitchyomega[.]pro |
| GraphQL Network Inspector | ndlbedplllcgconngcnfmkadhokfaaln | 29 Dec 2024 | graphqlnetwork[.]pro |
| YesCaptcha assistant | jiofmdifioeejeilfkpegipdjiopiekl | 29 Dec 2024 | yescaptcha[.]pro |
| Castorus | mnhffkhmpnefgklngfmlndmkimimbphc | 26 Dec 2024 | castorus[.]info |
| Uvoice | oaikpkmjciadfpddlpjjdapglcihgdle | 26 Dec 2024 | uvoice[.]live |
| VidHelper - Video Download Helper | egmennebgadmncfjafcemlecimkepcle | 26 Dec 2024 | videodownloadhelper[.]pro |
| ParrotTalks | kkodiihpgodmdankclfibbiphjkfdenh | 25 Dec 2024 | parrottalks[.]info |
| Bookmark Favicon Changer | acmfnomgphggonodopogfbmkneepfgnh | 25 Dec 2024 | bookmarkfc[.]info |
| Internxt VPN | dpggmcodlahmljkhlmpgpdcffdaoccni | 25 Dec 2024 | internxtvpn[.]pro |
| Vidnoz Flex | cplhlgabfijoiabgkigdafklbhhdkahj | 25 Dec 2024 | vidnozflex[.]live |
| Cyberhaven | pajkjnmeojmbapicmbpliphjmcekeaac | 24 Dec 2024 | cyberhavenext[.]pro |
| Wayin AI | cedgndijpacnfbdggppddacngjfdkaca | 19 Dec 2024 | wayinai[.]live |
| Reader Mode | llimhhconnjiflfimocjggfjdlmlhblm | 18 Dec 2024 | readermodeext[.]info |
| Primus (previously PADO) | oeiomhmbaapihbilkfkhmlajkeegnjhe | 18 Dec 2024 | primusext[.]pro |
| TinaMind | befflofjcniongenjmbkgkoljhgliihe | 15 Dec 2024 | tinamind[.]info |
| VPNCity | nnpnnpemnckcfdebeekibpiijlicmpom | 12 Dec 2024 | vpncity[.]live |
Reader Mode 1.5.7 is named as a compromised version by RH-ISAC. RH-ISAC also names Visual Effects for Google Meet 3.1.3, Email Hunter 1.4.4 and YesCaptcha Assistant 1.1.61. Cyberhaven version 24.10.4 was malicious. Version 24.10.5 is the clean release.
Indicators of compromise
- Command domains: see the table. Also
nagofsg[.]com,sclpfybn[.]comandtnagofsg[.]com. - Phishing domains:
chromewebstore-noreply[.]com,chromeforextension[.]com,supportchromestore[.]com. Redirect host:app.checkpolicy[.]site. - Configuration servers:
149.28.124[.]84and45.76.225[.]148. Exfiltration server:149.248.2[.]160. - SHA-256 of
background.js:b0827dc54349b10098a7370ada4ea44ba668b264ccca2db5676be1c32e6cc154. - SHA-256 of
context_responder.js:d303047205dabec8e2d34431e920ebe3478ca80a18f57bf454da094aca0e10aa. - Local storage keys in the extension that end in
_ext_manage. - OAuth application name "Privacy Policy Extension" in a developer account.
How to check
Look for the extension IDs in your browser profiles. On macOS:
ls ~/Library/Application\ Support/Google/Chrome/*/Extensions | grep -E "hihblcmlaaademjlakdpicchbjnnnkbo|ndlbedplllcgconngcnfmkadhokfaaln|llimhhconnjiflfimocjggfjdlmlhblm|dpggmcodlahmljkhlmpgpdcffdaoccni|pajkjnmeojmbapicmbpliphjmcekeaac|nnpnnpemnckcfdebeekibpiijlicmpom"
This checks six of the IDs in the table. Add the rest to the pattern. Then search proxy and DNS logs for the command domains above. If you publish an extension, review the OAuth apps that can access your Web Store developer account.
What to do now
- Update or remove every extension in the table. Use only a version released after the clean fix.
- Revoke API keys, session tokens and passwords that those browsers held, for example OpenAI and Facebook credentials.
- Block the domains and IP addresses above.
- Developers: remove the "Privacy Policy Extension" OAuth app, change your password and enable strong two-factor sign-in.
- Remember that Chrome Web Store messages come from the Chrome developer dashboard. Do not use links in a policy-warning email.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 23 (2 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE background.js It downloads from the internet and reads saved passwords and access keys.
Frequently asked questions
Which Chrome extensions were compromised in December 2024?
More than 35 extensions were hit. Examples are Cyberhaven, Reader Mode, Proxy SwitchyOmega V3, GraphQL Network Inspector, Internxt VPN, VPNCity, ParrotTalks and Uvoice.
How did attackers get into the Chrome Web Store developer accounts?
They sent phishing emails that looked like Chrome Web Store policy warnings. The link asked developers to approve a malicious OAuth app that can publish extension updates.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.