Listen to this Post

Introduction
For years, browser extensions have been marketed as the friendly helpers of the web, quietly improving productivity, cleaning clutter, or offering stylish customization. Users trust them, developers update them, and marketplaces verify them. Yet beneath this comfortable illusion, a slow and methodical threat actor was playing a very different game. The group now known as ShadyPanda spent seven years embedding itself into the daily browsing habits of millions, waiting patiently before flipping the switch that turned harmless extensions into silent surveillance probes.
What unfolded is one of the largest browser-extension compromises ever recorded. A sprawling infiltration across both Chrome and Microsoft Edge, a meticulous trust-building operation, and a technically sophisticated espionage system that hid in plain sight. The story is both an exposé and a warning: even the extensions we trust most can become weaponized with a single update.
Main Summary
ShadyPanda, a newly identified threat actor, orchestrated a seven-year browser extension campaign that infected at least 4.3 million users across Google Chrome and Microsoft Edge. What makes this operation remarkable is not just its scale but its strategy. Rather than releasing obviously malicious extensions, ShadyPanda played the long game. It began by publishing legitimate add-ons in 2018 and 2019, slowly gaining trust, accumulating users, and earning coveted labels such as Featured or Verified in Google’s extension marketplace.
Once the extensions gained a large user base and marketplace credibility, everything changed. In mid-2024, ShadyPanda pushed a malicious update that turned these popular tools into remote code execution backdoors. This enhancement allowed the attackers to send fresh JavaScript payloads every hour from an attacker-controlled domain, gaining full access to browser APIs. With this access, each infected browser became a controllable implant capable of spying, injecting content, or hijacking online accounts.
The attackers did not stop at simple monitoring. The malicious payload collected every visited URL, timestamps, referral paths, cross-device UUIDs, and full browser fingerprints. Everything was encrypted using AES and sent to a dedicated exfiltration server hosted under the Clean Masters brand. ShadyPanda even deployed layers of anti-analysis techniques. The malicious functions shut down whenever developer tools were opened, obfuscation made reverse engineering difficult, and a built-in JavaScript interpreter helped bypass browser security rules.
Parallel to this backdoor operation, ShadyPanda also maintained a massive spyware network involving five Microsoft Edge extensions from a developer named Starlab Technology. These extensions, still live in the Edge Add-ons store, collectively have over 4 million installations. The most prominent one, WeTab New Tab Page, tracks almost everything a user does. It monitors URLs, search queries as they are typed, precise mouse movements, interaction patterns, and storage access. All this data flows to seventeen different domains, including several servers in China and Google Analytics endpoints.
What makes these extensions especially dangerous is their broad permissions. They can access all URLs, read cookies, and update silently. This means ShadyPanda can convert them into RCE backdoors at any time or escalate into deeper espionage. Koi Security’s research traces the group’s evolution through four phases. It began in 2023 with a cluster of over one hundred wallpaper and productivity extensions that hijacked e-commerce traffic. By early 2024, ShadyPanda expanded into search hijacking and cookie theft. The third phase involved long-term trust building, with the final stage resulting in full weaponization through malicious updates.
The most disturbing part of this story is not just the malware. It is the systemic failure of the extension marketplace model. Chrome and Edge both rely heavily on trust signals like verified status, developer history, and static code review at submission. What they lack is continuous behavioral monitoring. Once an extension is installed, its updates are trusted automatically. That system allows a malicious actor to push a single update that instantly transforms millions of legitimate installations into a surveillance or RCE network.
Koi Security highlights this weakness and positions behavioral monitoring as the necessary solution. Rather than relying on claimed functionality or a one-time review, the company advocates for real-time observation of extension behavior after installation. Only continuous scrutiny can detect the moment an extension turns rogue.
The ShadyPanda incident stands as a stark reminder that the trust we place in browser extensions can be exploited at scale. As long as marketplaces rely on static checks, any extension with enough patience can eventually become an attack vector.
What Undercode Say
The ShadyPanda campaign is a masterclass in strategic deception. Most malware threats are loud, fast, and designed for quick profit. ShadyPanda chose patience. They understood that modern security systems are built around the idea of static trust. If an extension behaves well for long enough, users and marketplaces stop looking. In cybersecurity, trust is often the easiest vulnerability to exploit.
The technical depth of the attack shows a threat actor with significant resources. Deploying an embedded JavaScript interpreter inside a browser extension is not something an amateur group would attempt. It suggests a team familiar with browser internals and capable of bypassing baked-in protections such as Content Security Policy. Layering anti-analysis systems on top of that reinforces a clear intent to avoid detection for as long as possible.
What stands out even more is the use of silent updates as a weapon. Browser extension infrastructures were designed for convenience. Users expect automatic updates. Developers rely on them for rolling out bug fixes or new features. ShadyPanda turned that convenience into an attack mechanism. This tactic is not new, but the scale at which they applied it is unprecedented.
Koi Security’s findings also highlight a broader issue. Modern browsers carry enormous power. They store passwords, manage sessions, handle authentication cookies, and touch almost every digital service a user interacts with. An extension with broad permissions gains access to a shadow version of the user’s digital life. ShadyPanda exploited this privilege to its fullest potential, turning browsers into perfect surveillance platforms.
Marketplace ecosystems bear equal responsibility in this incident. Verification labels tend to give users a false sense of security. A green badge or Featured tag makes an extension seem trustworthy, but these approvals are not re-evaluated when an extension updates. A malicious actor who is patient enough can gain legitimacy simply by behaving well until the moment they are ready to act.
The most alarming discovery is the active presence of spyware extensions still available in the Edge Add-ons store. With millions of installations, these tools continue to harvest massive datasets. The permissions they hold could escalate into RCE at any time, making them ticking time bombs. The fact that they remain active reflects how slowly marketplace ecosystems respond to complex threats.
What does this mean for users? It reveals a hidden layer of risk in everyday browsing. Most people treat extensions as harmless tools, not as potential implants. The events unfolding here should push the industry toward stronger behavioral analysis models. Static reviews cannot defend against strategic patience. Security requires real-time checks, automated anomaly detection, and the ability to revoke updates quickly.
ShadyPanda’s operation is not merely an attack. It is a warning that the weakest link in modern browsing is the assumption that trust is permanent.
🔍 Fact Checker Results
Verified that ShadyPanda compromised at least 4.3 million users. ✅
Confirmed that multiple extensions were weaponized through malicious updates. ✅
Verified that several spyware extensions remain active in the Edge store at publication time. ❌ (Status may change based on rapid removals)
📊 Prediction
ShadyPanda’s campaign will likely ignite renewed scrutiny of extension marketplaces. 🔥
Browser vendors may move toward behavior-first monitoring instead of static code checks. 🔧
Expect copycat threat actors to adopt similar long-game strategies in the coming year. 🚨
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




