PULSE NAME
Targeted supply chain attack against Chrome browser extensions - Sekoia.io Blog
WHITE CyberHunter_NL 2025-01-29 Modified: 2025-02-28
76
IOCs
HIGH VOLUME
A security firm, Sekoia, has uncovered a supply chain attack against Chrome browser extensions, which it believes may have been carried out since at least 2023 and possibly even earlier, according to its analysis.
Indicators of Compromise (76)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain email
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 28b4c68a46bb7701e5e0be57b9a1c320 MD5 of d303047205dabec8e2d34431e920ebe3478ca80a18f57bf454da094aca0e10aa 2025-01-29
FileHash-MD5 443e497e77fd349a40417a261caffa21 MD5 of b0827dc54349b10098a7370ada4ea44ba668b264ccca2db5676be1c32e6cc154 2025-01-29
FileHash-MD5 4e42ac21ed5898fd75221a2f1164a107 2025-01-29
FileHash-MD5 b4690045862e6c21fb180dd6dcb6b6b3 2025-01-29
FileHash-SHA1 25c2714c758042a402c9c946da10505367358531 SHA1 of d303047205dabec8e2d34431e920ebe3478ca80a18f57bf454da094aca0e10aa 2025-01-29
FileHash-SHA1 cb612c82f8c81ab607ee5ed86598ea3b7d472993 SHA1 of b0827dc54349b10098a7370ada4ea44ba668b264ccca2db5676be1c32e6cc154 2025-01-29
FileHash-SHA256 b0827dc54349b10098a7370ada4ea44ba668b264ccca2db5676be1c32e6cc154 2025-01-29
FileHash-SHA256 d303047205dabec8e2d34431e920ebe3478ca80a18f57bf454da094aca0e10aa 2025-01-29
URL https://app.checkpolicy.site/accept-terms-policy?e=victim@example.com 2025-01-29
URL https://app.checkpolicy.site/extension-privacy-policy?e=victime@example.com 2025-01-29
URL https://graphqlnetwork.pro/ai-graphqlnetwork 2025-01-29
domain adsblockforyoutube.site 2025-01-29
domain adskiper.net 2025-01-29
domain aiforgemini.com 2025-01-29
domain bardaiforchrome.live 2025-01-29
domain blockforads.com 2025-01-29
domain bookmarkfc.info 2025-01-29
domain castorus.info 2025-01-29
domain censortracker.pro 2025-01-29
domain chataiassistant.pro 2025-01-29
domain chatgptextension.site 2025-01-29
domain chatgptextent.pro 2025-01-29
domain chatgptforsearch.com 2025-01-29
domain checkpolicy.site 2025-01-29
domain chromeforextension.com 2025-01-29
domain chromewebstore-noreply.com 2025-01-29
domain cyberhavenext.pro 2025-01-29
domain dearflip.pro 2025-01-29
domain extensionbuysell.com 2025-01-29
domain extensionpolicy.net 2025-01-29
domain extensionpolicyprivacy.com 2025-01-29
domain geminiaigg.pro 2025-01-29
domain geminiforads.com 2025-01-29
domain goodenhancerblocker.site 2025-01-29
domain gpt4chrome.live 2025-01-29
domain gptdetector.live 2025-01-29
domain gptforads.info 2025-01-29
domain gptforbusiness.site 2025-01-29
domain graphqlnetwork.pro 2025-01-29
domain internetdownloadmanager.pro 2025-01-29
domain internxtvpn.pro 2025-01-29
domain iobit.pro 2025-01-29
domain linewizeconnect.com 2025-01-29
domain locallyext.ink 2025-01-29
domain moonsift.store 2025-01-29
domain openaigptforgg.site 2025-01-29
domain parrottalks.info 2025-01-29
domain pieadblock.pro 2025-01-29
domain policyextension.info 2025-01-29
domain primusext.pro 2025-01-29
domain promptheusgpt.info 2025-01-29
domain proxyswitchyomega.pro 2025-01-29
domain readermodeext.info 2025-01-29
domain savechatgpt.site 2025-01-29
domain savegpt.pro 2025-01-29
domain savegptforchrome.com 2025-01-29
domain savegptforyou.live 2025-01-29
domain savgptforchrome.pro 2025-01-29
domain searchaiassitant.info 2025-01-29
domain searchcopilot.co 2025-01-29
domain searchgptchat.info 2025-01-29
domain supportchromestore.com 2025-01-29
domain tinamind.info 2025-01-29
domain ultrablock.pro 2025-01-29
domain uvoice.live 2025-01-29
domain videodownloadhelper.pro 2025-01-29
domain vidnozflex.live 2025-01-29
domain vpncity.live 2025-01-29
domain wakelet.ink 2025-01-29
domain wayinai.live 2025-01-29
domain yescaptcha.pro 2025-01-29
domain youtubeadsblocker.live 2025-01-29
domain ytbadblocker.com 2025-01-29
domain yujaverity.info 2025-01-29
email chromewebstore-noreply@chromeforextension.com 2025-01-29
email chromewebstore-noreply@supportchromestore.com 2025-01-29