I Quit My Job After the Cyberhaven Breach. Here's What I've Been Building.
Christmas Eve, 2024. Most security teams were on holiday. Attackers compromised Cyberhaven's Chrome extension and pushed a malicious update to 400,000+ users. A security company — breached through a browser extension.
I was watching this unfold in real-time. And one thing became painfully obvious:
Nobody was watching the browser extensions.
Companies spend millions on endpoint detection, SIEM, firewalls, zero trust architectures. But the browser — the application where employees spend 90% of their workday — was a blind spot. Extensions with full page access, cookie permissions, and the ability to read everything you type? Installed with a single click, no security review, no monitoring.
The Moment It Clicked
I'd been working in security for years. After the Cyberhaven breach, I started digging. The more I looked, the worse it got:
- At least 35 other Chrome extensions were compromised using the same methodology
- Over 2.6 million users affected in that single attack wave
- Most enterprises had zero visibility into what extensions their employees were running
Security teams were reviewing code PRs line by line but had no idea what browser extensions had access to their corporate data.
That's when I decided to build what I wished existed.
December 2024: I Left My Job
I quit. No safety net, no co-founder, no funding. Just a conviction that browser extension security was going to become a critical enterprise need — and that whoever built the definitive platform first would own the category.
I started building Extension Auditor.
What I've Built (So Far)
14 months later, Extension Auditor tracks 534,026 browser extensions — one of the largest datasets of its kind. Here's what the platform does:
- Continuous monitoring of every Chrome extension in the Web Store
- Risk scoring powered by ML analysis across 140 features extracted from 55 academic papers
- Permission drift detection — know when an extension silently requests new dangerous permissions
- Publisher change tracking — get alerted when an extension changes ownership (a key attack vector)
- Version-level analysis — every update is analyzed, not just the initial install
The data tells a story: of the 534,000+ extensions we track, 42% have been removed from the Chrome Web Store. That's nearly 226,000 extensions that were once available — and potentially installed on your employees' browsers — that Google decided shouldn't exist anymore.
Why This Matters Now
Browser extensions are the next frontier of supply chain attacks. They have:
- Direct access to page content, cookies, and session tokens
- The ability to modify web requests in real-time
- Auto-update mechanisms that can push malicious code silently
- A trust model based on a single developer's Google account
The Cyberhaven breach wasn't an anomaly. It was a preview.
What's Next
I'm building Extension Auditor to be the default security layer for browser extensions in every enterprise. We're just getting started, and I'll be sharing more about the journey — the data, the discoveries, and the things that keep CISOs up at night.
If your security team doesn't have visibility into browser extensions, it's not a matter of if you'll have a problem. It's when.
Follow along. This is going to get interesting.
Ishan Girdhar is the founder of Extension Auditor, the browser extension security platform. extensionauditor.com