The MEGA Chrome Extension Supply Chain Attack
Updated 5 Oct 2026 · Incident date 4 Sept 2018 · browser extension
MEGA Chrome extension 3.39.3 -> 3.39.4 (fixed in 3.39.5)manifest.jsonMEGA Chrome extension 3.39.4 is a malicious build that an attacker uploaded to the Chrome Web Store on 4 September 2018. It asked for wider permissions and then stole logins and cryptocurrency keys.
MEGA published a clean 3.39.5 about four hours later. Roughly 1.6 million users had the extension installed, according to BleepingComputer.
What happened
At 14:30 UTC on 4 September 2018, an attacker uploaded a trojanized MEGA extension, version 3.39.4, to the Chrome Web Store. MEGA said the attacker used its publisher account on the store. MEGA also said that Google had removed the option for publishers to sign their own extensions, so Google signs the package after upload. BleepingComputer and The Hacker News report this.
The new build asked for a permission that reads and changes data on the websites you visit. Chrome showed this as a permission prompt. The extension then watched for logins on Amazon, Microsoft, GitHub and Google. It also watched the cryptocurrency sites MyEtherWallet, MyMonero and IDEX. It sent the data by HTTP POST to megaopac.host, a server in Ukraine.
The SerHack analysis adds more detail. The injected script watched form submissions where the URL contains "Register" or "Login". It also read wallet addresses and private keys from the MyEtherWallet and MyMonero pages. The code loaded at window load instead of sitting in the extension file.
Google removed the extension from the store at 19:19 UTC. Namecheap blocked the C2 domain at 20:19 UTC, per SerHack. MEGA said that the Firefox extension and the mega.nz website were not affected.
The first sign of the attack was a manifest change. Vigilance compares the version you trust with the new one and reports a new permission or a new file that gains a capability.
Affected versions
Only MEGA Chrome extension 3.39.4 is affected.
- 3.39.3: last clean version.
- 3.39.4: malicious, uploaded 4 September 2018 at 14:30 UTC.
- 3.39.5: clean version that replaced it.
A user was at risk if the browser auto-updated to 3.39.4 and the user accepted the new permission, or if the user installed 3.39.4 fresh. The Firefox version was not affected.
Indicators of compromise
These indicators come from SerHack and BleepingComputer.
- Extension version
3.39.4in the Chrome extension list. - Network traffic to the domain
megaopac[.]host. - IPv4 address
176.119.1[.]146, hosted in Ukraine, per SerHack. - A TLS certificate with the common name
la02abd2.justinstalledpanel.com, per SerHack. - A permission prompt that asked to read and change all data on the websites you visit.
How to check
Open the extension list in Chrome and read the MEGA version. Then search your DNS and proxy logs for the C2 domain.
chrome://extensions
On a managed network, search the DNS log for the domain.
grep -i "megaopac.host" /var/log/dns/*.log
The log path is an example. Use the path of your own resolver or proxy. Any hit from 4 September 2018 means a machine ran the bad build.
What to do now
- Update MEGA to 3.39.5 or later, or remove the extension.
- Change the passwords for Amazon, Microsoft, GitHub, Google and any other account you used while 3.39.4 was active.
- Treat cryptocurrency private keys as stolen if you used MyEtherWallet, MyMonero or IDEX in that period. Move the funds to a new wallet.
- Block
megaopac.hostand the IP address above on the network. - Review extension permissions. Remove any extension that asks for access to all websites without a clear need.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 85 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED manifest.json It now reads saved passwords and access keys and changes file permissions. It did not before.
Frequently asked questions
Which MEGA Chrome extension version was compromised?
Version 3.39.4, uploaded to the Chrome Web Store on 4 September 2018. Version 3.39.5 is the clean replacement.
What did the compromised MEGA extension steal?
It stole logins for sites such as Amazon, Microsoft, GitHub and Google, and private keys for MyEtherWallet, MyMonero and IDEX. It sent the data to megaopac.host.
Was the MEGA Firefox extension affected?
No. MEGA said the Firefox extension and the mega.nz website were not affected.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- QuickLens / ShotBird ownership-transfer hijack 17 Feb 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.