All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

ShadyPanda's 7-Year Malware Campaign Infected 4.3 Million Browsers Through Malicious Extensions

By

janpio

6mo ago· 7 min readenNews

Summary

Koi researchers have uncovered a seven-year malware campaign by threat actor ShadyPanda that infected 4.3 million Chrome and Edge browsers through malicious extensions. The campaign includes two active operations: a 300,000-user remote code execution backdoor through five extensions (including Clean Master) that now download and execute arbitrary JavaScript hourly, and a larger 4 million-user data theft operation through 34 extensions that steal browsing history, passwords, and cryptocurrency wallet data. The malware evaded detection for years by appearing legitimate before being weaponized.

Key quotes

· 5 pulled
Five extensions, including the 'Featured' and 'Verified' Clean Master, were weaponized in mid-2024 after years of legitimate operation.
These extensions now run hourly remote code execution - downloading and executing arbitrary JavaScript with full browser access.
The second operation is a 4 million-user data theft campaign using 34 extensions that steal browsing history, passwords, and cryptocurrency wallet data.
ShadyPanda's campaign has evaded detection for seven years by maintaining a facade of legitimacy before weaponizing extensions.
The malware's ability to bypass Chrome Web Store security measures highlights significant vulnerabilities in browser extension ecosystems.
Snippet from the RSS feed
ShadyPanda’s seven-year campaign infected 4.3 million browsers, spreading malware undetected and endangering user security worldwide.

You might also wanna read