Cyberhaven Chrome Extension Hacked in Christmas Day Supply Chain Attack
Hackers compromise a Cyberhaven developer account to push a malicious Chrome extension update that steals session tokens and passwords. The company quickly removes the compromised version and urges all affected users to rotate their credentials immediately.
Data-loss prevention startup Cyberhaven suffers a suspected supply-chain attack after hackers compromise a company account to publish a malicious update to its Chrome extension on Christmas morning. The compromised version 24.10.4 actively exfiltrates sensitive information, including authenticated sessions and cookies, to an attacker-controlled domain. Cyberhaven confirms the cyberattack but declines to provide specific details about the breach.
Cyberhaven's security team detects the compromise on the afternoon of December 25 and quickly removes the malicious extension from the Chrome Web Store. The company replaces it with a clean version 24.10.5 to halt the attack. The affected browser extension currently boasts approximately 400,000 corporate users, with prominent clients like Motorola, Reddit, and Snowflake potentially impacted by the incident.
The startup advises affected customers to immediately revoke and rotate all passwords and text-based credentials, such as API tokens, while reviewing internal logs for signs of malicious activity. Because stolen session tokens and cookies allow hackers to bypass password and two-factor authentication requirements, this breach poses a severe security risk to corporate networks. Cyberhaven does not disclose the exact number of customers it notifies about the incident.