Cyber startup employee hacked to distribute malicious Chrome extension
Dec. 30, 2024, 8:25 a.m.
Tags
External References
Description
Several Chrome extensions have been compromised, including those related to Cyberhaven. The affected extensions are linked to multiple suspicious domains resolving to the same IP address as cyberhavenext[.]pro. Some confirmed compromised extensions are listed with their corresponding URLs. Users are advised to search for these extensions in their environments and monitor for any traffic to the IP address 149.28.124[.]84. This information suggests a widespread attack targeting browser extensions, potentially putting users' data and privacy at risk.
Date
Published: Dec. 27, 2024, 2:21 p.m.
Created: Dec. 27, 2024, 2:21 p.m.
Modified: Dec. 30, 2024, 8:25 a.m.
Attack Patterns
T1567
T1176
T1071
T1102
T1059