The third-party Chrome extension Copyfish recently got hacked. As a result, the hackers were able to inject malicious JavaScript code into the code base and use it to display ads on all the pages users who had the extension installed viewed.
It took Copyfish’s developers a full day to realize they had been breached, and by that time, the hacker had transferred the extension to his own developer account, where it was beyond the reach of its original owners.