35 Google Chrome Extensions Hacked to Inject Malicious Code: What to Do
A massive phishing campaign compromised 35 popular Google Chrome extensions, affecting millions of users and extracting sensitive information. This blog provides an in-depth look at the attack, the affected extensions, and the steps you should take to protect yourself.
Quick answer: In a reported campaign, attackers phished the developers of Chrome extensions, took over their Web Store accounts and pushed malicious updates to about 35 extensions. Because Chrome updates extensions automatically, users received the code without doing anything. Protect yourself by removing unused extensions, restricting site access, reviewing permissions and, in organisations, allow-listing extensions.
Key takeaways
- The attack targeted extension developers, then used the normal update channel to reach users.
- An extension with permission to read all sites can see cookies, forms and session data.
- Remove what you do not use, limit site access and review permissions regularly.
- Organisations should allow-list extensions and monitor for permission changes.
What was reported
Security researchers reported a campaign in which attackers sent phishing emails to Chrome extension developers, posing as Chrome Web Store support. The emails pushed developers to authorise a malicious application through an OAuth consent screen. With that access, attackers could publish new versions of the developers' extensions. Reports named about 35 extensions and a combined user count of around 2.6 million. These figures come from researcher and press reports, so check the primary write-ups before quoting them. The aim was to steal data such as session information and credentials, with particular interest in advertising accounts on social media.
The older version of this article gave a specific date for the incident. That date does not match the reporting I know of, so it has been removed. Confirm timing against the original researchers' publications.
Why this works: the supply-chain problem
You trusted the extension, and the extension was updated by someone who was not its author. That is a supply-chain attack. Chrome extensions update silently, so a clean extension can become malicious overnight. Nothing was wrong with your browser or your habits. The weak point was the developer's account.
An extension that can "read and change all your data on all websites" can see what you type, read page content and steal cookies for logged-in sessions. That is why permissions matter more than the extension's reputation.
Audit your extensions in ten minutes
- Open
chrome://extensionsin Chrome. - For each extension, ask: do I use this weekly? If not, remove it.
- Click Details. Under Site access, change broad "On all sites" to On click or On specific sites wherever possible.
- Read the permissions list. A colour picker should not need access to every site.
- Check the developer name, the Web Store listing, recent reviews and the last update date. Sudden changes of owner or permissions are a warning.
- Use a separate browser profile for banking and admin work, with almost no extensions.
- Keep Chrome updated and enable Safe Browsing.
If you ran an extension named in a credible incident report, remove it, sign out of sensitive accounts, change passwords from a clean device, revoke active sessions and enable MFA. If money or accounts were affected in India, report at cybercrime.gov.in.
For organisations
- Allow-list extensions using Chrome enterprise policies, and block everything else.
- Review permissions before approving, and re-review after updates that add permissions.
- Inventory installed extensions on managed devices.
- Protect extension developer accounts if you publish extensions: phishing-resistant MFA, careful review of OAuth consent requests and a separate account for publishing.
- Monitor for unusual outbound traffic from browsers to unknown domains.
For developers
Treat any email about your store listing as suspicious. Go to the Chrome Web Store dashboard directly, never through a link. Review which third-party apps have access to your Google account. Use a security key.
The same risk elsewhere
Code editor and browser add-ons share this risk. See Firefox extensions that steal crypto wallets and malicious VS Code extensions.
Next steps
Understanding supply-chain and web-session risks is a core security skill. The Cyber Security course covers it, and the OWASP Top 10 lists the web risks behind session theft.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0