Targeted supply chain attack against Chrome browser extensions

Jan. 22, 2025, 4:48 p.m.

Description

In December 2024, a threat actor successfully compromised around a dozen legitimate Chrome browser extensions by exploiting extension developers' permissions gained through phishing attacks. The malicious code injected into the compromised extensions aimed to harvest sensitive user data like API keys, session cookies, and authentication tokens from websites such as ChatGPT and Facebook for Business. The analysis sheds light on the targeted phishing campaign, the adversary's infrastructure, and provides remediation steps along with technical indicators.

Date

  • Created: Jan. 22, 2025, 4:27 p.m.
  • Published: Jan. 22, 2025, 4:27 p.m.
  • Modified: Jan. 22, 2025, 4:48 p.m.

Indicators

  • d303047205dabec8e2d34431e920ebe3478ca80a18f57bf454da094aca0e10aa
  • b0827dc54349b10098a7370ada4ea44ba668b264ccca2db5676be1c32e6cc154
  • 185.92.222.127
  • 149.248.56.63
  • 144.202.101.155
  • 140.82.45.42
  • 136.244.113.231
  • 65.20.99.178
  • 45.77.5.196
  • 45.76.225.148
  • 155.138.253.165
  • 149.28.117.236
  • 149.248.44.88
  • 149.248.2.160
  • 137.220.48.214
  • 136.244.115.219
  • 108.61.23.192
  • 149.28.124.84
  • https://graphqlnetwork.pro/ai-graphqlnetwork
  • https://app.checkpolicy.site/extension-privacy-policy?e=victime@example.com
  • https://app.checkpolicy.site/accept-terms-policy?e=victim@example.com
  • chromewebstore-noreply@supportchromestore.com
  • chromewebstore-noreply@chromeforextension.com
  • savegpt.pro
  • promptheusgpt.info
  • openaigptforgg.site
  • internxtvpn.pro
  • gpt4chrome.live
  • chromewebstore-noreply.com
  • chataiassistant.pro
  • adsblockforyoutube.site
  • savegptforchrome.com
  • savegptforyou.live
  • geminiforads.com
  • goodenhancerblocker.site
  • chatgptforsearch.com
  • ytbadblocker.com
  • youtubeadsblocker.live
  • wakelet.ink
  • vidnozflex.live
  • videodownloadhelper.pro
  • ultrablock.pro
  • tinamind.info
  • searchgptchat.info
  • searchcopilot.co
  • searchaiassitant.info
  • savgptforchrome.pro
  • savechatgpt.site
  • pieadblock.pro
  • locallyext.ink
  • linewizeconnect.com
  • internetdownloadmanager.pro
  • gptforads.info
  • graphqlnetwork.pro
  • gptforbusiness.site
  • gptdetector.live
  • geminiaigg.pro
  • extensionpolicy.net
  • extensionpolicyprivacy.com
  • extensionbuysell.com
  • cyberhavenext.pro
  • dearflip.pro
  • checkpolicy.site
  • chatgptextent.pro
  • chatgptextension.site
  • blockforads.com
  • bardaiforchrome.live
  • aiforgemini.com
  • adskiper.net
  • supportchromestore.com
  • chromeforextension.com
  • parrottalks.info
  • yujaverity.info
  • wayinai.live
  • uvoice.live
  • primusext.pro
  • policyextension.info
  • moonsift.store
  • iobit.pro
  • castorus.info