A data-loss prevention startup has confirmed that hackers published a malicious update to its Chrome extension, which was capable of stealing customer passwords and session tokens. A new legitimate version of the extension was released soon after. The breach may have affected up to 400,000 corporate customer users.
The hackers compromised a company account to publish the malicious update, which could have allowed them to steal sensitive information, including authenticated sessions and cookies. Affected users are advised to revoke and rotate all passwords and review their logs for malicious activity. The company has initiated a comprehensive review of its security practices and is implementing additional safeguards.