PULSE NAME
Targeted supply chain attack against Chrome browser extensions
WHITE AlienVault 2025-01-22 Modified: 2025-02-21
66
IOCs
HIGH VOLUME
In December 2024, a threat actor successfully compromised around a dozen legitimate Chrome browser extensions by exploiting extension developers' permissions gained through phishing attacks. The malicious code injected into the compromised extensions aimed to harvest sensitive user data like API keys, session cookies, and authentication tokens from websites such as ChatGPT and Facebook for Business. The analysis sheds light on the targeted phishing campaign, the adversary's infrastructure, and provides remediation steps along with technical indicators.
Indicators of Compromise (2 / 66 total)
All FileHash-MD5 FileHash-SHA256 URL domain email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 4e42ac21ed5898fd75221a2f1164a107 2025-01-22
FileHash-MD5 b4690045862e6c21fb180dd6dcb6b6b3 2025-01-22