BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ShadyPanda Spyware Hits 4.3M Browsers via Malicious Extensions

ShadyPanda’s 7-Year Browser Extension Campaign Infects Over 4.3 Million Users with Malicious JavaScript and Data Theft

  • A threat actor named ShadyPanda conducted a seven-year browser extension campaign with over 4.3 million installations.
  • Five extensions initially legitimate were altered in mid-2024 to execute malicious JavaScript hourly.
  • Extensions collected encrypted browsing history, detailed browser fingerprints, and could perform man-in-the-middle attacks.
  • A set of five other add-ons, including WeTab with three million installs, tracked user activity and sent data to servers in China.
  • Users are advised to remove these extensions and change credentials due to risks from silent malicious updates via trusted update channels.

A group known as ShadyPanda has been tied to a persistent browser extension campaign spanning seven years, accumulating more than 4.3 million installs. In mid-2024, five extensions that previously operated legitimately were updated to run remote code execution, downloading and running arbitrary JavaScript with full browser control, according to a report by Malware-campaign”>Koi Security. These extensions have since been removed.

- Advertisement -

Security researcher Tuval Admoni explained that these extensions monitored every website visit, exfiltrated encrypted browsing histories, and captured complete browser fingerprints. One of the affected extensions, Clean Master, was once verified by Google, allowing the attackers to silently push malicious updates without drawing attention.

An additional five extensions, including WeTab which alone had three million downloads from the Microsoft Edge Addons store, were built to surveil users by recording URLs visited, search engine queries, mouse clicks, and transmitting this information to Chinese servers. These add-ons also tracked interaction details like time spent on pages and scrolling behavior.

Initial suspicious activity appeared in 2023, with around 20 extensions on Chrome and 125 on Edge published under developer names “nuggetsno15” and “rocket Zhang.” These extensions disguised themselves as wallpaper or productivity tools and conducted affiliate fraud by injecting tracking codes on sites like eBay, Booking.com, and Amazon to illicitly generate commission.

By early 2024, the campaign escalated to direct browser control, intercepting and redirecting searches, harvesting search data, and stealing cookies from targeted domains. The malicious updates introduced a backdoor communicating with the domain “api.extensionplay[.]com” to retrieve harmful JavaScript hourly.

- Advertisement -

The extensions sent collected data in encrypted form to a server at “api.cleanmasters[.]store” while also employing obfuscation techniques to evade detection. They switched behavior to benign mode if developer tools were accessed. These extensions also enabled adversary-in-the-middle (AitM) attacks, which can steal credentials, hijack sessions, and inject code into websites.

Users who installed any of the flagged extensions are strongly advised to uninstall them immediately and update their passwords due to the high risk of surveillance and credential theft. As stated in the report, “The auto-update mechanism – designed to keep users secure – became the attack vector”, allowing trusted marketplaces to inadvertently distribute malware through silent updates.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto bros fake luxury buys for dopamine rush

Crypto bros with stagnating portfolios are turning to “dopamine shopping” to experience the thrill...

Tether downplays exposure to bank in $84M seizure

Tether confirmed limited exposure to EQIBank, representing just 0.034% of its total assets.US prosecutors...

Bitget CEO Confirms North Korea Behind $352M Crypto Hack

Bitget lost approximately $352 million in a hack attributed to North Korea's Lazarus Group.CEO...

No confirmed crypto theft in iPhone Safari attack: SlowMist.

SlowMist has not confirmed any cryptocurrency theft linked to the Safari attack it analyzed,...

Bitget hacked: $351.6M stolen by North Korea

Bitget lost $351.6 million from hot and warm wallets on September 24, 2026, in...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading