Security researchers have uncovered a seven-year malware campaign that may have infected more than four million trusted Chrome and Edge browser extensions.
Investigating the activities of the threat group dubbed ‘ShadyPanda’, cybersec outfit Koi discovered two active operations that provided hackers with the means to spy on users and harvest browsing data, including from enterprise firms unlucky enough to be running the compromised extensions.
Koi’s analysis revealed that black‑hat actors weaponised five extensions in mid-2024, after years of legitimate operation, in an active campaign thought to have impacted 300,000 users.
These malicious installs, which included the popular Clean Master extension, resulted in a Remote Code Execution (RCE) backdoor, with the malware allowing unrestricted browser access, letting hackers track every website visited and capture encrypted browsing histories.
In a second, ongoing campaign, Koi uncovered that threat actors had compromised another five browser extensions, including the widely used WeTab, in a sophisticated spyware operation that harvested every mouse click, search query, and URL visited.
Koi claimed that this operation has ensnared four million browser users, with the data collected transmitted back to servers in China.
According to Koi, ShadyPanda has been playing a long game. Its first campaign in 2023 exploited more than 250 Chrome and Edge extensions to run affiliate fraud, slipping in tracking codes that skimmed hidden commissions from users’ online purchases.
That passive, money-making operation quickly became something more nefarious, with the group targeting active browser control by early 2024.
Disguising its malware as a new tab productivity tool, ShadyPanda redirected web searches through a known browser hijacker, logging user activity to be monetised and sold, all while compiling detailed user profiles.
However, those efforts pale in comparison to the hacker’s grand plan, which saw extensions first uploaded as far back as 2018 operate legitimately for years, gaining Featured and Verified status on both marketplaces, and taking in hundreds of thousands of victims.
After hitting some ambiguous download number, ShadyPanda pushed the big red button, sending an automatic infection via Chrome and Edge’s trusted auto-update mechanism. All five extensions that Koi investigated now run identical malware.
While those earlier extensions were recently removed from marketplaces, Koi said that the infrastructure for full-scale attacks is still a threat to those who have already downloaded the add-ons.
Koi further warned that the most dangerous extensions from ShadyPanda’s latest campaign are still available for download. While the Edge store seems to have removed WeTab, as of writing, a version of the add-on is still accessible via Google’s Chrome store.
This could be particularly bad news for unwitting enterprises that either use these extensions or allow employees to do so, with browser‑based logins to SaaS platforms, cloud consoles, and internal tools, exposed to threat actors. Worse, infected developer machines could translate into compromised code repositories and stolen API keys.
Recommended reading
- Is OpenAI’s Atlas Browser ‘Inherently Dangerous’?
- Report: Only 2.8% of Websites Protected Against AI Bots
- Chrome to Make HTTPS Default in 2026
The success of ShadyPanda’s operation is evidence that browser marketplaces are not robust enough in the face of evolving threat tactics.
Once these extensions had been reviewed at the point of submission, ShadyPanda was in full control, making Chrome and Edge’s trusted update pipeline a security risk.
“One patient threat actor and one lesson: Trust is the vulnerability,” wrote Tuval Admoni, a security researcher at Koi, when laying out the firm’s findings.
“ShadyPanda proved that marketplaces still review extensions the same way they did seven years ago – static analysis at submission, trust after approval, no ongoing monitoring. Clean Master operated legitimately for five years. Static analysis wouldn’t catch this.”





