BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ShadyPanda Spyware Hits 4.3M Browsers via Malicious Extensions

ShadyPanda’s 7-Year Browser Extension Campaign Infects Over 4.3 Million Users with Malicious JavaScript and Data Theft

  • A threat actor named ShadyPanda conducted a seven-year browser extension campaign with over 4.3 million installations.
  • Five extensions initially legitimate were altered in mid-2024 to execute malicious JavaScript hourly.
  • Extensions collected encrypted browsing history, detailed browser fingerprints, and could perform man-in-the-middle attacks.
  • A set of five other add-ons, including WeTab with three million installs, tracked user activity and sent data to servers in China.
  • Users are advised to remove these extensions and change credentials due to risks from silent malicious updates via trusted update channels.

A group known as ShadyPanda has been tied to a persistent browser extension campaign spanning seven years, accumulating more than 4.3 million installs. In mid-2024, five extensions that previously operated legitimately were updated to run remote code execution, downloading and running arbitrary JavaScript with full browser control, according to a report by Malware-campaign”>Koi Security. These extensions have since been removed.

- Advertisement -

Security researcher Tuval Admoni explained that these extensions monitored every website visit, exfiltrated encrypted browsing histories, and captured complete browser fingerprints. One of the affected extensions, Clean Master, was once verified by Google, allowing the attackers to silently push malicious updates without drawing attention.

An additional five extensions, including WeTab which alone had three million downloads from the Microsoft Edge Addons store, were built to surveil users by recording URLs visited, search engine queries, mouse clicks, and transmitting this information to Chinese servers. These add-ons also tracked interaction details like time spent on pages and scrolling behavior.

Initial suspicious activity appeared in 2023, with around 20 extensions on Chrome and 125 on Edge published under developer names “nuggetsno15” and “rocket Zhang.” These extensions disguised themselves as wallpaper or productivity tools and conducted affiliate fraud by injecting tracking codes on sites like eBay, Booking.com, and Amazon to illicitly generate commission.

By early 2024, the campaign escalated to direct browser control, intercepting and redirecting searches, harvesting search data, and stealing cookies from targeted domains. The malicious updates introduced a backdoor communicating with the domain “api.extensionplay[.]com” to retrieve harmful JavaScript hourly.

- Advertisement -

The extensions sent collected data in encrypted form to a server at “api.cleanmasters[.]store” while also employing obfuscation techniques to evade detection. They switched behavior to benign mode if developer tools were accessed. These extensions also enabled adversary-in-the-middle (AitM) attacks, which can steal credentials, hijack sessions, and inject code into websites.

Users who installed any of the flagged extensions are strongly advised to uninstall them immediately and update their passwords due to the high risk of surveillance and credential theft. As stated in the report, “The auto-update mechanism – designed to keep users secure – became the attack vector”, allowing trusted marketplaces to inadvertently distribute malware through silent updates.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BitGo Q1 Loss Widens Despite Revenue Jump, Client Growth

BitGo reported a Q1 2026 net loss of $60.7 million, widened by $53.7 million...

Linux Fragnesia CVE-2026-46300 LPE Vulnerability Uncovered

A new Linux kernel vulnerability dubbed "Fragnesia" (CVE-2026-46300) allows unprivileged local attackers to gain...

BRICS Shun US Dollar for $214B Yuan Trade Amid Sanctions

BRICS nations Russia and Iran settled $214 billion in trade using the Chinese yuan...

Moody’s: Digital Shift Will Start Slow, Then Go Fast

Major US banks and financial intermediaries expect a digital financial transition to start slowly,...

Coinbase CEO Backs Revised Crypto Clarity Act Ahead of Senate Markup

Coinbase CEO Brian Armstrong endorses the latest bipartisan Digital Asset Market Clarity Act ahead...

Must Read

How to Buy VPS with Crypto from Hostinger – Step by Step guide

Did you know that nowadays you can use Bitcoin to purchase a Windows VPS? If you’re here, you’re probably wondering how to do it....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading