The MEGA Chrome Extension Supply Chain Attack

Updated 5 Oct 2026 · Incident date 4 Sept 2018 · browser extension

PackageMEGA Chrome extension 3.39.3 -> 3.39.4 (fixed in 3.39.5)
Filemanifest.json

MEGA Chrome extension 3.39.4 is a malicious build that an attacker uploaded to the Chrome Web Store on 4 September 2018. It asked for wider permissions and then stole logins and cryptocurrency keys.

MEGA published a clean 3.39.5 about four hours later. Roughly 1.6 million users had the extension installed, according to BleepingComputer.

What happened

At 14:30 UTC on 4 September 2018, an attacker uploaded a trojanized MEGA extension, version 3.39.4, to the Chrome Web Store. MEGA said the attacker used its publisher account on the store. MEGA also said that Google had removed the option for publishers to sign their own extensions, so Google signs the package after upload. BleepingComputer and The Hacker News report this.

The new build asked for a permission that reads and changes data on the websites you visit. Chrome showed this as a permission prompt. The extension then watched for logins on Amazon, Microsoft, GitHub and Google. It also watched the cryptocurrency sites MyEtherWallet, MyMonero and IDEX. It sent the data by HTTP POST to megaopac.host, a server in Ukraine.

The SerHack analysis adds more detail. The injected script watched form submissions where the URL contains "Register" or "Login". It also read wallet addresses and private keys from the MyEtherWallet and MyMonero pages. The code loaded at window load instead of sitting in the extension file.

Google removed the extension from the store at 19:19 UTC. Namecheap blocked the C2 domain at 20:19 UTC, per SerHack. MEGA said that the Firefox extension and the mega.nz website were not affected.

The first sign of the attack was a manifest change. Vigilance compares the version you trust with the new one and reports a new permission or a new file that gains a capability.

Affected versions

Only MEGA Chrome extension 3.39.4 is affected.

A user was at risk if the browser auto-updated to 3.39.4 and the user accepted the new permission, or if the user installed 3.39.4 fresh. The Firefox version was not affected.

Indicators of compromise

These indicators come from SerHack and BleepingComputer.

How to check

Open the extension list in Chrome and read the MEGA version. Then search your DNS and proxy logs for the C2 domain.

chrome://extensions

On a managed network, search the DNS log for the domain.

grep -i "megaopac.host" /var/log/dns/*.log

The log path is an example. Use the path of your own resolver or proxy. Any hit from 4 September 2018 means a machine ran the bad build.

What to do now

  1. Update MEGA to 3.39.5 or later, or remove the extension.
  2. Change the passwords for Amazon, Microsoft, GitHub, Google and any other account you used while 3.39.4 was active.
  3. Treat cryptocurrency private keys as stolen if you used MyEtherWallet, MyMonero or IDEX in that period. Move the funds to a new wallet.
  4. Block megaopac.host and the IP address above on the network.
  5. Review extension permissions. Remove any extension that asks for access to all websites without a clear need.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old extension-3.39.3 --new extension-3.39.4
files scanned: 85

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    manifest.json
           It now reads saved passwords and access keys and changes file permissions. It did not before.

Frequently asked questions

Which MEGA Chrome extension version was compromised?

Version 3.39.4, uploaded to the Chrome Web Store on 4 September 2018. Version 3.39.5 is the clean replacement.

What did the compromised MEGA extension steal?

It stole logins for sites such as Amazon, Microsoft, GitHub and Google, and private keys for MyEtherWallet, MyMonero and IDEX. It sent the data to megaopac.host.

Was the MEGA Firefox extension affected?

No. MEGA said the Firefox extension and the mega.nz website were not affected.

Sources

  1. bleepingcomputer.com/news/security/mega-chrome-extension-hacked-to-steal-login-credentials-and-cryptocurrency/
  2. thehackernews.com/2018/09/mega-file-upload-chrome-extension.html
  3. serhack.me/articles/mega-chrome-extension-hacked/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free