Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard Highly sophisticated supply chain attack started with a phishing email.
The researchers said the attack starts with a very convincing phishing attack, in which the threat actors impersonated Google Chrome Web Store support.
Hackers have managed to compromise dozens of legitimate Google Chrome extensions in what appears to be a highly sophisticated supply chain attack.
Sekoia says that the threat actors were going after Facebook Business accounts, API keys, session cookies, access tokens, account information, and ad account details.
They sent emails to Chrome extension developers, warning them about violated store policies, and having their work removed from the store unless they “extended their privacy policy”.