The compromised version of this proxy-switching tool, version 24.10.4, was infiltrated with malicious code after a phishing email targeted an employee at Cyberhaven, an AI-powered data security company. The email falsely claimed that Cyberhaven’s browser extension violated Google’s policies and threatened removal unless immediate action was taken, allowing attackers to use OAuth to access the account and upload the harmful update, unbeknownst to users installing it.
The incident highlights the vulnerability of browser extensions to cyberattacks, a tactic not new to the crypto space—cybersecurity experts note that groups like the North Korean Lazarus Group have long targeted crypto professionals and developers through similar methods, such as fake video apps and compromised extensions, with intensified efforts reported in September 2024 by Group-IB. Stay informed on crypto security threats with
Crypto Market Insights on news.thecoininfo.com, and explore in-depth analysis on The Coin Info Hub at thecoininfo.com.