Supply Chain Monitoring
Chrome updates extensions behind your back
The extension your team approved last month is not necessarily the extension running today. We re-run the full analysis pipeline on every version update, so you know when something changes.
Real incident: December 2024
A developer's Chrome Web Store account was compromised via a phishing email. The attacker pushed malicious updates to 35+ extensions in a single night - including Cyberhaven, with 400,000 enterprise users. The updates used the exact same permissions as the legitimate versions. Every permission-based scanner showed no change. Chrome auto-updated the extensions on employee devices within hours.
The only way to catch this is to re-analyse the code on every update - which is what we do.
How it works
Update detection
We run scraping infrastructure across the Chrome Web Store to detect new extension versions. When a new version is published, it enters the analysis pipeline automatically - target SLO: ingestion within 2 hours of publication, p95.
Full pipeline re-run
The new version goes through the same analysis as the original - deobfuscation, static claim formation, dynamic sandbox execution, network capture, evidence collection, and claim verification. Not a diff of the source. A full independent analysis of what the new version does.
Comparison against prior version
The new analysis is compared against the previous version's results. New network destinations, obfuscated code that wasn't there before, a risk score that has jumped - any of these trigger an alert to your dashboard and configured notification channels.
What triggers an alert
- Malware or vulnerabilities found in a new version that wasn't in the previous one
- Risk score change above your configured threshold
- New concerning behavior
Know when a trusted extension turns malicious.
Set up fleet monitoring in under 48 hours.

