A researcher named SerHack first alerted users via a tweet mentioning the hacked extension. He noticed that the tool potentially harvested user credentials from various platforms, including Microsoft, Github, Google, and Amazon.
https://twitter.com/serhack_/status/1037026672787304450
- serhack_
He shared various screenshots in his tweets to prove his discovery. Later, he posted a detailed timeline of the events on his blog, which indicated that the news first broke on Reddit about the malicious MEGA Extension on Chrome. It also mentioned all other instances where various researchers shared their work regarding the attack.
https://www.reddit.com/r/Monero/comments/9cx7cc/dont_use_mega_chrome_extension_version_3394/
The malicious extension came to be noticed when it asked for “elevated permissions” unlike the genuine MEGA Extension. After harvesting the data, the tool sent the user information to a local server at megaopac[.]host in Ukraine. After the breach was confirmed, NameCheap blocked the megaopac[.]host domain.
While MEGA did not state any specific number of affected users, SerHack told Bleeping Computer that the hack affected over 1.6 million users.
They publicly disclosed about it in their blog and confirmed that version 3.39.5 is the genuine version to replace the hacked one. Google also removed the malicious tool five hours after the incident.
MEGA confirmed that the breach affected only the users of version 3.39.4. As stated in their blog,
“You are only affected if you had the MEGA Chrome extension installed at the time of the incident, autoupdate enabled and you accepted the additional permission, or if you freshly installed version 3.39.4. Please note that if you visited any site or made use of another extension that sends plain-text credentials through POST requests, either by direct form submission or through a background XMLHttpRequest process (MEGA is not one of them) while the trojaned extension was active, consider that your credentials were compromised on these sites and/or applications.”
“We would like to apologise for this significant incident. MEGA uses strict release procedures with multi-party code review, robust build workflow and cryptographic signatures where possible. Unfortunately, Google decided to disallow publisher signatures on Chrome extensions and is now relying solely on signing them automatically after upload to the Chrome webstore, which removes an important barrier to external compromise. MEGAsync and our Firefox extension are signed and hosted by us and could therefore not have fallen victim to this attack vector. While our mobile apps are hosted by Apple/Google/Microsoft, they are cryptographically signed by us and therefore immune as well.”Users with MEGA Chrome Extension version 3.39.4 should quickly get rid of this malicious tool by upgrading to the 3.39.5. Moreover, they should also closely monitor their crypto assets and change their login credentials and private keys to mitigate the effect.
Take your time to comment on this article.