ABCDEFGHIJKLMNOPQRSTUVWXYZAAABACAD
1
NameIDVersionPatchAvailableUsersStartEndCode FamilyNotes
2
VPNCitynnpnnpemnckcfdebeekibpiijlicmpom2.0.1FALSE1000012/12/2412/31/241Removed from the web store 12/31/24
3
Parrot Talkskkodiihpgodmdankclfibbiphjkfdenh1.16.2TRUE4000012/25/2412/31/241
Attacker infrastructure offline 12/31, code likely still present.
4
Uvoiceoaikpkmjciadfpddlpjjdapglcihgdle1.0.12TRUE4000012/26/2412/31/241
Attacker infrastructure offline 12/31, code likely still present.
5
Internxt VPNdpggmcodlahmljkhlmpgpdcffdaoccni1.1.11.2.0TRUE1000012/25/2412/29/241
6
Bookmark Favicon Changeracmfnomgphggonodopogfbmkneepfgnh4.00TRUE4000012/25/2412/31/241
Attacker infrastructure offline 12/31, code likely still present.
7
Castorusmnhffkhmpnefgklngfmlndmkimimbphc4.404.41TRUE5000012/26/2412/27/241
8
Wayin AIcedgndijpacnfbdggppddacngjfdkaca0.0.11TRUE4000012/19/2412/31/241
Attacker infrastructure offline 12/31, code likely still present.
9
Search Copilot AI Assistant for Chromebbdnohkpnbkdkmnkddobeafboooinpla1.0.1TRUE200007/17/2412/31/241
Attacker infrastructure offline 12/31, code likely still present.
10
VidHelper - Video Downloaderegmennebgadmncfjafcemlecimkepcle2.2.7TRUE2000012/26/2412/31/241
Attacker infrastructure offline 12/31, code likely still present.
11
AI Assistant - ChatGPT and Gemini for Chromebibjgkidgpfbblifamdlkdlhgihmfohh0.1.3FALSE40005/31/2410/25/241Removed from the web store 10/25/24
12
TinaMind - The GPT-4o-powered AI Assistant!befflofjcniongenjmbkgkoljhgliihe2.13.02.14.0TRUE4000012/15/2412/20/241
13
Bard AI chatpkgciiiancapdlpcbppfkmeaieppikkk1.3.7FALSE1000009/5/2410/22/241Removed from the web store 10/22/24
14
Reader Modellimhhconnjiflfimocjggfjdlmlhblm1.5.7FALSE30000012/18/2412/19/241 & 2Removed from the web store 12/19/24
15
Primus (prev. PADO)oeiomhmbaapihbilkfkhmlajkeegnjhe3.18.03.20.0TRUE4000012/18/2412/25/241
16
Tackker - online keylogger toolekpkdmohpdnebfedjjfklhpefgpgaaji1.31.4TRUE1000010/6/238/13/242
17
AI Shop Buddyepikoohpebngmakjinphfiagogjcnddm2.7.3TRUE40004/30/242Two version of exploit code present
18
Sort by Oldestmiglaibdlgminlepgeifekifakochlka1.4.5TRUE20001/11/242
19
Rewards Search Automatoreanofdhdfbcalhflpbdipkjjkoimeeod1.4.9TRUE1000005/4/242
Two versions of exploit code present. Version 1.5.0 published August 26th, 2024 removed one of them.
20
Earny - Up to 20% Cash Backogbhbgkiojdollpjbhbamafmedkeockb1.8.1TRUE100004/5/233
21
ChatGPT Assistant - Smart Searchbgejafhieobnfpjlpcjjggoboebonfcg1.1.1TRUE1892/12/242
22
Keyboard History Recorderigbodamhgjohafcenbcljfegbipdfjpk2.3TRUE50007/29/242
23
Email Huntermbindhfolmpijhodmgkloeeppmkhpmhc1.44TRUE1000009/17/242
Region locked on the web store. Accessed from France and India.
24
Visual Effects for Google Meethodiladlefdpcbemnbbcpclbmknkiaem3.1.33.2.4TRUE9000006/13/231/10/242 & 3
25
Cyberhaven security extension V3pajkjnmeojmbapicmbpliphjmcekeaac24.10.424.10.5TRUE40000012/24/2412/26/241
26
GraphQL Network Inspectorndlbedplllcgconngcnfmkadhokfaaln2.22.62.22.7TRUE8000012/29/2412/30/241
2.22.5 (clean) was also published on 12/29/24 so multiple code pushes in the same day
27
GPT 4 Summary with OpenAIepdjhgbipjpbbhoccdeipghoihibnfja1.4FALSE10,0008/11/249/29/241
Removed from the web store 9/29/24. May have started earlier.
28
Vidnoz Flex - Video recorder & Video sharecplhlgabfijoiabgkigdafklbhhdkahj1.0.161FALSE6,00012/25/2412/29/241Removed from the web store 12/29/24
29
YesCaptcha assistantjiofmdifioeejeilfkpegipdjiopiekl1.1.61TRUE200,00012/29/2412/31/241
Attacker infrastructure offline 12/31, extension has been updated
30
Proxy SwitchyOmega (V3)hihblcmlaaademjlakdpicchbjnnnkbo3.0.2FALSE10,00012/30/2412/31/241
Attacker infrastructure offline 12/31, extension has been upaded
31
ChatGPT Applbneaaedflankmgmfbmaplggbmjjmbae1.3.8TRUE7,0009/3/242May have started earlier, missing data right now
32
Web Mirroreaijffijbobmnonfhilihbejadplhddo2.4TRUE4,00010/13/232May have started earlier, missing data right now
33
Hi AIhmiaoahjllhfgebflooeeefeiafpkfde1.0.0TRUE2297/29/242May have started earlier, missing data right now
34
2,602,418
35
Detailed information at: https://secureannex.com/blog/cyberhaven-extension-compromise
36
37
Code family definitions
38
1: Most recent attacks with code that uses '*ext.[pro|co|info|ink]" domains
1,460,000
39
2: Attacks with code using 'sclpfybn[.]com'1,142,418
40
3: Attacks with oldest code using 'tnagofsg[.]com' references
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100