Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

Benchmark raises $225 million in special funding to double Cerebras

AI startup founder says he plans a ‘March for Billionaires’ to protest California’s wealth tax

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » ShadyPanda turns popular browser extension with 4.3 million installs into spyware
Identity

ShadyPanda turns popular browser extension with 4.3 million installs into spyware

userBy userDecember 1, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

The threat actor known as ShadyPanda has been involved in a seven-year browser extension campaign that has resulted in over 4.3 million installs.

According to a report by Koui Security, five of these extensions started as legitimate programs and introduced malicious changes in mid-2024, garnering 300,000 installations. These extensions have since been removed.

“These extensions are currently performing remote code execution every hour, downloading and executing arbitrary JavaScript with full browser access,” security researcher Tuval Admoni said in a report shared with The Hacker News. “They monitor every website visit, steal encrypted browsing history, and collect complete browser fingerprints.”

To make matters worse, one of the extensions, Clean Master, was picked up and verified by Google at some point. This trust-building exercise allowed the attackers to expand their user base and silently issue malicious updates years later without arousing any suspicion.

Meanwhile, another set of five add-ons from the same publisher is designed to monitor every URL a user visits, record search engine queries and mouse clicks, and send that information to a server located in China. These extensions have been installed approximately 4 million times, with WeTab alone accounting for 3 million installs.

cyber security

Early signs of malicious activity were said to have been observed in 2023, when 20 extensions were published on the Chrome Web Store and 125 extensions on Microsoft Edge by developers named “nuggetsno15” and “rocket Zhang,” respectively. All identified extensions were masquerading as wallpapers or productivity apps.

These extensions have been found to engage in affiliate fraud by secretly injecting tracking codes when users visit eBay, Booking.com, or Amazon to generate illegal commissions from users’ purchases. In early 2024, attacks moved from seemingly benign injections to active browser control by redirecting search queries, harvesting search queries, and extracting cookies from specific domains.

“All web searches were redirected through trovi.com, a known browser hijacker,” Coy said. “Search queries are recorded, monetized, and sold. Search results are manipulated for profit.”

At some point in mid-2024, five extensions (three of which had been working legally for years) were modified to distribute malicious updates that introduced backdoor-like functionality by checking the domain “api.extensionplay.”[.]com” every hour to retrieve and execute a JavaScript payload.

The payload is designed to monitor all visits to the website and send the data in encrypted format to ShadyPanda servers (“api.cleanmasters”).[.]In addition to using extensive obfuscation to hide its functionality, it also switches the browser to benign behavior when you attempt to access the browser’s developer tools.

Additionally, extensions can launch man-in-the-middle (AitM) attacks to facilitate credential theft, session hijacking, and arbitrary code injection into websites.

This activity moved into its final phase when five other extensions, including WeTab, published to the Microsoft Edge Add-on Hub around 2023, leveraged its huge installed base to enable comprehensive monitoring of all visited URLs, search queries, mouse clicks, cookies, browser fingerprint collection, and more.

It also has the ability to collect information about how victims interact with web pages, such as web page viewing time and scrolling behavior. The WeTab extension is still available for download as of this writing.

cyber security

The findings provide a complete picture of an ongoing campaign that occurred over four distinct phases, gradually transforming browser extensions from legitimate tools to data-gathering spyware. However, it is worth noting that it is not clear whether the attackers artificially inflated the download numbers to create an illusion of legitimacy.

We recommend that users who have installed the extension remove the extension immediately and rotate their credentials out of an abundance of caution.

“The automatic update mechanism designed to keep users safe became an attack vector,” Coy said. “Chrome and Edge’s trusted update pipeline delivered malware to users silently. No phishing, no social engineering, just trusted extensions with silent version bumps that turn a productivity tool into a monitoring platform.”

“ShadyPanda’s success goes beyond technical sophistication; it has systematically exploited the same vulnerability for seven years. The marketplace reviews extensions at the time of submission; we do not monitor what happens after approval.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAI-generated images of cats on bananas exist because children scavenge in the soil for toxic substances. Is it really worth it?
Next Article India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud
user
  • Website

Related Posts

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

February 7, 2026

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

February 6, 2026

China-linked DKnife AitM framework, routers targeted for traffic hijacking and malware distribution

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

Benchmark raises $225 million in special funding to double Cerebras

AI startup founder says he plans a ‘March for Billionaires’ to protest California’s wealth tax

From Svedka to Anthropic, brands are boldly leveraging AI in their Super Bowl ads

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.