Cyberhaven’s Chrome extension was manipulated with a phishing email sent to developers. Following the incident, it transpired that another 19 Chrome extensions had been compromised, affecting 1.46 million downloads. The earliest compromise dates back to May 2024. The successful attacks were due to ineffective management and monitoring of browser extensions as part of company’s security programs. The breach seemingly has its roots in a code library used by developers to monetise their extensions.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.