United States
USA
A phishing attack on December 24, 2024 compromised a Cyberhaven employee's Chrome Web Store access, allowing an attacker to publish malicious version 24.10.4 of Cyberhaven's legitimate browser extension. The trusted update channel exposed downstream corporate users to theft of authenticated sessions and cookies until the malicious version was removed and replaced. Public reporting characterized the event as part of a broader campaign against Chrome extension developers; no specific actor was confirmed.
Estimated severity
72 / 100
Source reliability
93 / 100
Approximate Date
24/12/2024
Targeted Company
CYBERHAVEN
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
No information
Impacted regions
No information
Duration
1.25 days
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone