A hacker compromised the Hola VPN developer account, and replaced the official Chrome extension with a copycat, which redirected MyEtherWallet users to a fake phishing website he operated.

The breach occurred yesterday and the defaced version of the Chrome extension was available for download for just 5 hours, according to a tweet from the MyEtherWallet (MEW) team. Hola VPNadmitted to the breach in a post on its website.
“We have contacted and informed MEW, as well as Google, and have confirmed that the hacker’s copycat site is no longer available,” Hola developers said. The original Hola VPN extension is back in the Chrome web store. The team did not say how their account was compromised, but many Chrome extension developers have been victims of phishing attacks over the past year.
The MEW team asked for the attention of its users in a tweet, and suggested that all users switch to new accounts if they logged into the service in the last 24 hours. However, not all users were affected. Only those who upgraded the extension (the upgrade is done automatically) and used the MEW service should switch to new accounts, for security reasons.
Finally, it is worth mentioning that although this attack was quite complex, it was not the first time that MEW has fallen victim to hackers. In April, the service fell victim to a DNS hijacking attack, where when users tried to enter the site, instead of the real one, they were led to a fake, but visually identical page. In this way, the hackers stole the credentials from user accounts, and in total they managed to steal more than $ 160,000. So far, we do not know if the hackers have extracted any money with yesterday's attack.
