The attack, which began on Christmas Eve, exploited a vulnerability in the Chrome Web Store’s developer authentication system. Attackers used sophisticated spear-phishing techniques to gain access to the accounts of extension developers, enabling them to upload malicious versions of popular extensions.
Widespread cyberattack targets Google Chrome extensions, compromises 2.6 million devices
