35 Chrome Extensions Hacked, 2.6 Million Users Exposed - See If You're Affected

By Chandramohan Rajput      |     Jan 03, 2025

NEWS

Massive Extension Breach

Hackers have escalated their campaign, compromising 35 Chrome extensions used by more than 2.6 million people. The breach exposes growing risks in browser security.

7FB806

List of some Hacked Chrome Extensions

- Where is Cookie? - Web Mirror - ChatGPT App - Hi AI - Web3Password Manager - YesCaptcha assistant - Bookmark Favicon Changer - Proxy SwitchyOmega - GraphQL Network Inspector - AI Assistant - Bard AI chat - ChatGPT for Google Meet - Search Copilot AI Assistant for Chrome - TinaMind - Wayin AI - VPNCity - Internxt VPN - Vidnoz Flex - VidHelper - Castorus - Uvoice - Reader Mode

Targeted Phishing Emails

Developers received phishing emails mimicking Google policy violation notices. These emails tricked them into granting access to malicious apps.

OAuth Exploited to Bypass MFA

Attackers used a fake OAuth app to gain control of developer accounts. Multi-factor authentication didn’t prevent these breaches.

Malicious Code Injected

Malicious scripts were added to compromised extensions in order to steal sensitive information, with a focus on Facebook business accounts.

Focus on Facebook Accounts

The stolen data included Facebook IDs, cookies, and ad account information. Hackers intended to hijack and monetize accounts.

What You Should Do?

You should update your extensions right away, audit your installations, and keep an eye on your accounts for any unusual activity.