Today > | 2 Medium | 1 Low vulnerabilities   -   You can now download lists of IOCs here!

Cyber startup employee hacked to distribute malicious Chrome extension

Dec. 30, 2024, 8:25 a.m.

Description

Several Chrome extensions have been compromised, including those related to Cyberhaven. The affected extensions are linked to multiple suspicious domains resolving to the same IP address as cyberhavenext[.]pro. Some confirmed compromised extensions are listed with their corresponding URLs. Users are advised to search for these extensions in their environments and monitor for any traffic to the IP address 149.28.124[.]84. This information suggests a widespread attack targeting browser extensions, potentially putting users' data and privacy at risk.

Date

Published: Dec. 27, 2024, 2:21 p.m.

Created: Dec. 27, 2024, 2:21 p.m.

Modified: Dec. 30, 2024, 8:25 a.m.

Indicators

149.28.124.84

Attack Patterns

T1567

T1176

T1071

T1102

T1059