ShadyPanda's 7-Year Malware Campaign Infected 4.3 Million Browsers Through Malicious Extensions
By
janpio
Hot, fresh, and worth queueing round the block for.
Summary
Koi researchers have uncovered a seven-year malware campaign by threat actor ShadyPanda that infected 4.3 million Chrome and Edge browsers through malicious extensions. The campaign includes two active operations: a 300,000-user remote code execution backdoor through five extensions (including Clean Master) that now download and execute arbitrary JavaScript hourly, and a larger 4 million-user data theft operation through 34 extensions that steal browsing history, passwords, and cryptocurrency wallet data. The malware evaded detection for years by appearing legitimate before being weaponized.
Key quotes
· 5 pulledFive extensions, including the 'Featured' and 'Verified' Clean Master, were weaponized in mid-2024 after years of legitimate operation.
These extensions now run hourly remote code execution - downloading and executing arbitrary JavaScript with full browser access.
The second operation is a 4 million-user data theft campaign using 34 extensions that steal browsing history, passwords, and cryptocurrency wallet data.
ShadyPanda's campaign has evaded detection for seven years by maintaining a facade of legitimacy before weaponizing extensions.
The malware's ability to bypass Chrome Web Store security measures highlights significant vulnerabilities in browser extension ecosystems.
You might also wanna read
Microsoft uncovers cryptojacking campaign using SEO poisoning and AI chatbots to target high-GPU users via fake utility downloads
Microsoft Defender Experts identified an active cryptojacking campaign that uses SEO poisoning and AI chatbot manipulation to distribute mal
npm malware targeting Claude users leaks own GitHub token, reaches 676 downloads
An npm package called "mouse5212-super-formatter" targeting Claude users acted as information-stealing malware, reaching 676 downloads befor
Fake ChatGPT and Claude installers on GitHub and SourceForge deliver Deno RAT malware that steals crypto wallets
Attackers are distributing counterfeit installers for popular software like ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY o
MicrosoftSystem64 Malware Abuses HuggingFace Platform for Stealthy Data Theft
A newly discovered malware named MicrosoftSystem64 is stealing data from infected computers by exfiltrating files through HuggingFace, a leg
cybersecuritynews.com·2d ago