Full Breakdown
ShadyPanda's Malicious Browser Extension Campaign: A Seven-Year Infiltration
12/2/2025, 3:26:31 AM
Overview of the Malicious Campaign
ShadyPanda, a threat actor, has been linked to a seven-year-long campaign involving malicious browser extensions that have infected over 4.3 million users of Google Chrome and Microsoft Edge. Initially, five extensions, including Clean Master and WeTab, were legitimate tools before being modified to include malware, resulting in approximately 300,000 installations of the malicious versions. The campaign's evolution involved the introduction of remote code execution capabilities, allowing the malware to download and execute arbitrary JavaScript with full browser access.
Phases of the Attack
The ShadyPanda campaign unfolded in multiple phases. Early signs of malicious activity were noted in 2023, with 20 extensions on the Chrome Web Store and 125 on Microsoft Edge being published by developers identified as "nuggetsno15" and "rocket Zhang." These extensions, masquerading as wallpaper or productivity applications, engaged in affiliate fraud by injecting tracking codes into e-commerce sites like eBay and Amazon. By mid-2024, the attackers escalated their tactics, implementing backdoor functionalities that enabled extensive data collection and manipulation of user searches.
Technical Mechanisms
The malware utilized by ShadyPanda is sophisticated, employing extensive obfuscation techniques to hide its true functionality. It can execute adversary-in-the-middle (AitM) attacks, facilitating credential theft and session hijacking. The extensions are designed to monitor user interactions with web pages, including time spent and scrolling behavior. Notably, the auto-update mechanism, intended for user security, became the attack vector, allowing the malware to be silently delivered to users without their knowledge.
Current Status of the Extensions
As of now, some of the malicious extensions, including WeTab, remain available for download, despite their removal from the Chrome Web Store. Koi Security, which conducted the investigation, warns that the infrastructure for these attacks is still active, posing ongoing risks to users. The malware continues to collect sensitive data, such as browsing history and cookies, and sends this information to ShadyPanda-controlled servers.
Official Responses and Recommendations
Google confirmed that none of the malicious extensions are currently available on the Chrome Web Store and emphasized that all updates to extensions are screened. However, Microsoft has not publicly commented on the situation. Koi Security advises users who have installed these extensions to remove them immediately and change their credentials as a precautionary measure.
Criticism of Extension Management
The ShadyPanda campaign highlights significant flaws in the management of browser extensions by marketplaces. Researchers noted that while extensions are reviewed upon submission, there is no ongoing oversight, allowing malicious updates to go undetected for years. This lack of vigilance has enabled ShadyPanda to exploit the system effectively, turning trusted tools into surveillance platforms.
Verbatim Quotes
- “The auto-update mechanism – designed to keep users secure – became the attack vector,” — Koi Security
- “Chrome and Edge's trusted update pipeline silently delivered malware to users. No phishing. No social engineering. Just trusted extensions with quiet version bumps that turned productivity tools into surveillance platforms.” — Koi Security
- “ShadyPanda can push updates at any time, weaponizing 4 million browsers with the same RCE backdoor framework [from Clean Master] or something even worse.” — Koi Security
This ongoing situation underscores the need for improved monitoring and management of browser extensions to protect users from similar threats in the future.
