Cybercriminals Are Now Targeting Chrome Web Store Extensions To Access Users’ Personal Data: Reports

Main Image
  • Like
  • Comment
  • Share

While cases of Digital Arrest Scams are on the rise in India, another trend has begun globally. Apparently, cybercriminals are now targeting Chrome extension developers to gain access to a large number of users’ information. Most recently, a renowned company’s extension was compromised, and it wasn’t the only extension that bad actors targeted.

Also Read: Fraudsters Impersonating Investment Firm Duped Kerala Man of Rs. 4.05 Crore

What Happened With Cyberhaven’s Chrome Extension?

According to a report by Reuters, cybercriminals have started to target Chrome browser extensions to steal people’s information. According to Cyberhaven’s CEO (a data protection solutions company), a malicious cyberattack took place on the company’s Chrome extension on Christmas Eve.

Giving more details on what happened, the company states how a phishing attack compromised an employee’s credentials to access the Chrome Web Store. Then, the bad actors used the credentials to float a malicious version of Cyberhaven’s Chrome extension. The affected version of the extension is 24.10.4.

With this, the Chrome-based browsers that auto-download the update were affected. As mentioned in the blog, “the malicious code could have exfiltrated cookies and authenticated sessions for certain targeted websites.” More importantly, the attackers tried logging in to specific social media advertising platforms.

The company has taken all the countermeasures, including notifying all the affected users and removing the malicious version of the extension. Moreover, this was part of a larger campaign that targeted Chrome extension developers.

Also Read: E-Challan Scams: What You Need to Know to Stay Safe

Some Other Popular Chrome Extensions Are Also Under Attack

The co-founder of Nudge Security, Jaime Blasco, also told Reuters about spotting a couple of other Chrome Web Store extensions with malicious code. These include Internxt VPN, VPNCity, Uvoice, and ParrotTalks. Collectively, these extensions have about 140,000 users, which is a considerable number.

According to a more recent report by The Hacker News, a total of 16 hacked Chrome extensions have exposed over 600,000 users’ data to theft. As mentioned in the report, the bad actors used a phishing email, which claimed to be from the Google Chrome Web Store Developer’s support team.

The email mentioned how the extension would be removed from the Web Store if the developers didn’t act immediately. Further, the email requested the recipients to click on a link that asked for permission to make changes to the extension.

Also Read: Bollywood Actor Aftab Shivdasani Loses ₹1.5 Lakh in KYC Scam: 8 Tips to Stay Safe

Why Are Hackers Targeting Chrome Extensions Anyway?

Moreover, these are just a few extensions that experienced the same issue all at the same time. For those catching up, Chrome extensions often have access to sensitive information, such as browsing history, cookies, credentials, personal data like name, email address, and, in some cases, financial data.

Amid such a scenario, avid users of Google Chrome extensions should check whether the ones they use have reported any hacking incidents. If they have, users should remove the extensions, change the credentials that the extension had access to, and wait for the developers to release a safe version.

You can follow Smartprix on TwitterFacebookInstagram, and Google News. Visit smartprix.com for the most recent newsreviews, and tech guides

Shikhar MehrotraShikhar Mehrotra
Shikhar Mehrotra is a seasoned technology writer and reviewer with over five years of experience covering consumer tech across India and global markets. At Smartprix, he has authored more than 1,700 articles, including news stories, features, comparisons, and product reviews spanning automobiles, smartphones, chipsets, wearables, laptops, home appliances, and operating systems. Shikhar has reviewed flagship devices such as the iPhone 16, Galaxy S25+, and Sennheiser HD 505 Open-Ear headphones. He also contributes regularly to Smartprix’s growing automotive section.

With a deep understanding of both iOS and Android ecosystems, Shikhar specializes in daily tech news, how-to explainers, product comparisons, and in-depth reviews. His DSLR photography in product reviews is recognized as among the best on the team.

Before joining Smartprix, Shikhar wrote for leading publications including Forbes Advisor India, Republic World, and ScreenRant. He holds a Bachelor of Arts in Journalism and Mass Communication from Amity University, Lucknow.

Related Articles

ImageLIVE NOW: Best Motorola Phones To Buy During Flipkart Big Billion Days 2025

The Flipkart Big Billion Days 2025 sale is live, and now’s the time to get a new Motorola smartphone, especially if there’s one already added to your cart. From entry-level 5G handsets, affordable mid-rangers, to the most inexpensive flip-style phone on the market, you can purchase a desired handset right now, at excellent prices. So, …

ImageAirtel Down Today: Customers Struggle With Calls and Data Amid Major Outage

Airtel subscribers across India experienced a sudden service disruption on Monday afternoon, causing widespread issues for users attempting to make calls or access mobile data. Initial reports from outage tracker Downdetector indicated a surge in complaints around 3:30 PM IST, with over 3,600 incidents logged by the evening. What’s affected Downdetector data shows that 71% …

ImagePersonal Data of Over 81 Crore Indians Allegedly Leaked and Sold on Dark Web: Report

In a troubling revelation, it has been reported that the personal data of over 81 crore Indian citizens has been allegedly leaked and put up for sale on the dark web. The data in question pertains to COVID-19 test records and was reportedly stored by the Indian Council of Medical Research (ICMR). The breach came …

ImageGoogle Pulled the Plug On its Chrome Apps From the Chrome Web Store

True to its word, Google shut down its Apps service form the Chrome Web Store on all platforms except Chrome OS as was promised a year ago. The user of Windows, Linux and Mac will not be able to access or install any apps from the store. The Web Store will only have options for Extensions and …

ImageUser Spots A Standalone Google Gemini App For iPhone Users, Allows Access To Gemini Live

Although its target audience could be small, Google is apparently testing a dedicated Gemini app for iOS. Most recently, a Reddit user spotted the app in the App Store. With a standalone app, Google could provide faster updates and new features to iPhone users who prefer to use Google’s Gemini AI assistant. Also Read: How …

Discuss

Be the first to leave a comment.