Skip to main content
Back to overview
High

Cyberhaven Suffers Cyberattack via Phishing Campaign, Malicious Code Injected into Chrome Extension

Here’s What We Can Learn from the Cyberhaven Incident I.

Key points

  • Cyberhaven experienced a cyberattack, with the initial attack discovered on December 24, 2024.
  • A phishing campaign compromised a Cyberhaven employee's Chrome Web Store account.
  • Malicious code was injected into Cyberhaven's browser extension.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social, Hacking activity

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Dec 24, 2024
Updated
Jul 22, 2026
Confidence
High
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social, Hacking activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

CyberhavenData DisclosureCyberhaven Suffers CyberattackPhishing CampaignMalicious Code InjectedChrome Extension HereWhat We Can LearnCyberhavenChrome Web StoreThus

Quick context

Questions about this signal

What happened in this signal?

Here’s What We Can Learn from the Cyberhaven Incident I. Introduction to the Cyberhaven Security Incident In December 2024, Cyberhaven fell victim to a sophisticated cyberattack that exploited a phishing campaign targeting its Chrome Web Store account. This breach compromised over 400,000 users by injecting malicious code into its browser extension, exfiltrating sensitive data such as cookies and session tokens. The incident has drawn significant attention due to Cyberhaven's role as a cybersecurity provider and the broader implications for browser extension security. This was not a targeted attack on Cyberhaven alone but an opportunistic campaign exploiting multiple developers' credentials - over 35 extensions have been identified as compromised in the same fashion, affecting over 2.6M users. Thus, this is an important and evolving threat that is important to understand and derive lessons from. 1. Initial Attack Discovered - December 24, 2024 The breach began on December 24, when a Cyberhaven employee fell victim to a phishing attack. The attackers used a phishing campaign to compromise an administrative account associated with Cyberhaven's Chrome Web Store. A phishing email , disguised as official communication from Google Chrome Web Store Developer Support, claimed that Cyberhaven's extension violated policies and was at risk of removal. By granting permissions to this application, the attackers gained control of Cyberhaven's Chrome Web Store account . Using this access, they uploaded a malicious version (v24.10.4) of Cyberhaven's browser extension . This version included code to exfiltrate cookies, session tokens, and other sensitive data from users [1][2][4] . The malicious extension passed Chrome Web Store's security review. The attack leveraged OAuth authorization flows which bypassed multi=factor authentication (MFA). Although the employee was using MFA and had enabled Google's Advanced Protection, no MFA prompt was triggered during the OAuth process [7][8] . The malicious code installed took these forms and actions in their environment: Two key malicious files were added [9] .some text worker.js - Connected to C&C server for configuration downloads content.js - Handled data collection and exfiltration When users visited Facebook.com, extension collected [9] some text Facebook access tokens User and account details via Facebook APIs Extension monitored mouse clicks on Facebook.com to detect QR codes [9] Investigations began immediately after the breach was detected on December 25, with Cyberhaven engaging external incident response teams and notifying law enforcement [1][2][3] . ‍ 3. Attack Publicly Disclosed - December 27, 2024 Primary targets were Chrome Extension Developers with Facebook Ads account access A number of Cyberhaven's customers were impacted Investigation ongoing with third-party security response team 4. Immediate Breach Impact for Cyberhaven Customers The Cyberhaven breach was part of a broader campaign that targeted at least 35 Chrome extensions, collectively affecting approximately 2.6 million users. This campaign exploited a phishing attack aimed at Chrome extension developers, allowing attackers to gain unauthorized access to their Chrome Web Store accounts and inject malicious code into legitimate extensions.

When was this signal reported?

Shadow Tier lists Dec 24, 2024 as the signal date.

Which organization is connected to this signal?

Cyberhaven is the organization connected to this public signal.

Explore Cyberhaven
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence