MEGA File-Sharing Service’s Chrome Extension Hacked, Cryptocurrency Accounts Compromised

- Advertisement -

September 6, 2018 6:52 PM

A hacker uploaded a malicious version of the extension onto the Chrome Web Store.

MEGA, a New Zealand-based cloud storage and file hosting service, recently issued a security warning regarding a “trojaned” version of its extension that an unknown attacker uploaded to the Chrome Web Store. The malicious update, version 3.39.4, asked for permission to read and change data on websites that users visited. The MEGA team noted that affected sites included amazon.com, github.com, google.com, myetherwallet.com, and mymonero.com, among others.

Four hours after the security breach, MEGA updated the malicious version with a “clean” one (3.39.5). An hour after that, Google removed the extension from the Chrome Web Store. As of press, 3.40.2 is available for download.

- Advertisement -

Individuals were only affected by the hack if they had the MEGA Chrome extension installed when the attack occurred and had the auto-update feature enabled and accepted the additional permission request (or if they downloaded 3.39.4 directly from the web store). The MEGA crew further told users that if they visited any site during the attack, then they should “consider that [their] credentials were compromised on these sites and/or applications.”

Although the hack affected various data and information across multiple websites, the attack specifically exposed users’ cryptocurrency accounts associated with the extension. Both MyEtherWallet and Monero, for instance, warned their users about the compromise over Twitter:

Some MyEtherWallet users were also affected in July when the Hola Chrome extension was hacked.

The MEGA crew believes the recent incident is related to a change on Google’s end that disallows publisher signatures on Chrome extensions. Apparently, Google “is now relying solely on signing [extensions] automatically after upload to the Chrome webstore, which removes an important barrier to external compromise.” The team indicated that its Firefox extension would not have been able to experience this type of attack.

MEGA is looking into the nature of the hack.

Daniel Putney is a full-time writer for ETHNews. He received his bachelor’s degree in English writing from the University of Nevada, Reno, where he also studied journalism and queer theory. In his free time, he writes poetry, plays the piano, and fangirls over fictional characters. He lives with his partner, three dogs, and two cats in the middle of nowhere, Nevada.

Like what you read? Follow us on X @Bitnewsbot to receive the latest hack, MEGA or other Ethereum technology news.



Previous Articles:

- Advertisement -

Latest News

Coinbase txid used as private key sparks BTC bot RBF war now

Summarize the article from Yesterday, someone sent Bitcoin (BTC) to a compromised wallet that...

Goldman CEO: CLARITY Act ‘has a long way’ amidst stablecoins

David Solomon, CEO of Goldman Sachs, said staff are watching the Digital Asset Market...

Musk Gifts Cybertruck to xAI Employee After 24-Hour GPU Win.

Sulaiman Ghori of xAI said Elon Musk promised an employee a Cybertruck for completing...

Canaan Faces Nasdaq Delisting Unless Stock Tops $1 by July…

Canaan must raise its share price above $1 for 10 consecutive trading days by...

Analyst: Alphabet Could Hit $5T Market Cap by 2027 vs Nvidia

Alphabet briefly topped a $4.0 trillion market value in early 2026, hitting an all-time...
- Advertisement -

Must Read

How to Buy VPS with Crypto from Hostinger – Step by Step guide

Did you know that nowadays you can use Bitcoin to purchase a Windows VPS? If you’re here, you’re probably wondering how to do it....
Bitcoin (BTC) $ 95,502.00 0.05%
Ethereum (ETH) $ 3,293.49 0.17%
XRP (XRP) $ 2.08 0.26%
Bittensor (TAO) $ 279.44 0.08%
Polkadot (DOT) $ 2.13 1.19%
Cardano (ADA) $ 0.396795 1.17%
Chainlink (LINK) $ 13.72 0.58%
Hyperliquid (HYPE) $ 24.95 1.65%
Monero (XMR) $ 641.67 4.06%
Hedera (HBAR) $ 0.119545 2.62%
Toncoin (TON) $ 1.71 1.06%