Close Menu
Must Have Gadgets –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Sony Updates PS5, PS5 Slim to Address Liquid Metal Leak Problem

    December 3, 2025

    Fire and Ash’ Closes the First ‘Avatar’ Saga

    December 3, 2025

    Google quietly restores Screen-off Fingerprint Unlock on Pixels

    December 3, 2025
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Trending
    • Sony Updates PS5, PS5 Slim to Address Liquid Metal Leak Problem
    • Fire and Ash’ Closes the First ‘Avatar’ Saga
    • Google quietly restores Screen-off Fingerprint Unlock on Pixels
    • Grok would prefer a second Holocaust over harming Elon Musk
    • Google Photos 2025 Recap is here with the ability to hide unwanted faces
    • Gift Cozy Vibes With the SwitchBot Candle Warmer Lamp This Holiday Season
    • Last-Minute Cyber Week Gaming Laptop and Desktop Deals Are Still Available
    • How much will the Galaxy Z TriFold cost? I’m a Samsung expert and here’s my prediction
    • Home
    • Shop
      • Earbuds & Headphones
      • Smartwatches
      • Mobile Accessories
      • Smart Home Devices
      • Laptops & Tablets
    • Gadget Reviews
    • How-To Guides
    • Mobile Accessories
    • Smart Devices
    • More
      • Top Deals
      • Smart Home
      • Tech News
      • Trending Tech
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Home»Smart Home»This spyware campaign can turn your browser extensions into malware — how to stay safe
    Smart Home

    This spyware campaign can turn your browser extensions into malware — how to stay safe

    adminBy adminDecember 3, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    This spyware campaign can turn your browser extensions into malware — how to stay safe
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A long running malware operation that has evolved over several years has been turning browser extensions in Chrome and Edge into spyware through updates that added malicious functionalities. According to a report from Koi Security, the ShadyPanda campaign affects 4.3 million users who downloaded these now compromised browser extensions.

    The ShadyPanda campaign consists of 20 malicious extensions on the Chrome Web Store and 125 in Edge; initial submissions of the extensions appeared in 2018, and the first signs of malicious behavior didn’t show up until five years later when a set of them posing as wallpaper and productivity tools began to show signs that something was amiss.

    According to Koi Security, the malware campaign rolled out slowly, in phases, through the auto updated mechanism that is designed to keep users safe:


    You may like

    “Chrome and Edge’s trusted update pipeline silently delivered malware to users. No phishing. No social engineering. Just trusted extensions with quiet version bumps that turn productivity tools into surveillance platforms.”

    Here’s everything you need to know about this massive malicious extension campaign along with what steps you can take to secure your browser and your data right now.

    From fraud to full browser access

    (Image credit: Shutterstock)

    The extensions begin their malicious activity by injecting tracking codes into legitimate links, which allowed them to earn revenue off of users’ purchases. Search hijacking, where search queries are redirected, was also one of the behaviors the researchers saw. Search queries were logged, monetized, sold, manipulated and exfiltrated.

    ShadyPanda can collect a range of personal information from users including browsing history, search queries, keystrokes, cookies, local and session storage, fingerprint data, and mouse clicks with coordinates. The extensions that had gained a “good” reputation were modified throughout the years to include a backdoor update that permitted an hourly remote code execution; downloading and executing arbitrary JavaScript with full browser access. This means they were capable of monitoring every website a user visited and exfiltrating browsing URLs, fingerprinting information and persistent identifiers.

    Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

    Most concerningly, the extensions were able to stage adversary in the middle (AitM) attacks which means they were capable of facilitating credential theft, session hijacking and injecting code into any website. Additionally, any attempt to access the browser’s developer tools will cause it to switch to benign behavior.

    While Google has since removed the extensions from the web store, Koi Security noticed the active campaign in the Microsoft Edge Add-ons platform with one extension listed as having 3 million installs. There is no way of telling if those are inflated numbers, intended to create a sense of legitimacy though.

    How to stay safe from malicious browser extensions

    (Image credit: Getty Images)

    Most of these extensions are wallpaper or productivity apps and if you’ve downloaded any of them, you should remove them immediately. While Koi Security lists all the extensions at the end of their report, three of the most frequently mentioned ones are Clean Master, WeTab and Infinity V+.


    You may like

    After removing the extensions, you should reset your account passwords – the recommendation is for all accounts across your entire online presence. Since this could be quite a serious undertaking, you may want to use one of the best password managers to make things easier. Not only can a password manager help keep your passwords organized and safe but they can also automatically create strong and unique passwords for each of your online accounts.

    As always, I recommend using the best antivirus software on your computer as well. While an antivirus may not have caught these malicious extensions due to how this campaign operated, they can scan for malware, spyware and viruses even when you slip up and download something that shouldn’t be on your machine. Antivirus programs also have browser extensions that can help advise you against visiting suspicious websites, help protect your data with cloud backups and can provide you with a VPN and other extras to add an extra layer of security to protect you when you’re online.

    Given how successful and long-running this campaign was, I doubt this is the last we’ve heard of ShadyPanda. However, by limiting the number of extensions you have installed and carefully vetting each one before you add it to your browser, you can keep your data and your devices safe.

    Follow Tom’s Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds.

    More from Tom’s Guide

    SORT BYMonthly cost (low to high)Monthly cost (high to low)Product Name (A to Z)Product Name (Z to A)

    browser Campaign extensions malware safe Spyware stay turn
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Sony Updates PS5, PS5 Slim to Address Liquid Metal Leak Problem

    December 3, 2025

    YouTube Adds One More Year-End Recap, This Time for Your Viewing History

    December 3, 2025

    Cyber Week sales from $10 at Amazon, Walmart and Best Buy: 59+ extended holiday deals to shop right now

    December 3, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Sony Updates PS5, PS5 Slim to Address Liquid Metal Leak Problem

    December 3, 2025

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    October 16, 2025

    The best AirPods deals for October 2025

    October 16, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    How-To Guides

    How to Disable Some or All AI Features on your Samsung Galaxy Phone

    By adminOctober 16, 20250
    Gadget Reviews

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    By adminOctober 16, 20250
    Smart Devices

    The best AirPods deals for October 2025

    By adminOctober 16, 20250

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    Sony Updates PS5, PS5 Slim to Address Liquid Metal Leak Problem

    December 3, 2025

    Fire and Ash’ Closes the First ‘Avatar’ Saga

    December 3, 2025

    Google quietly restores Screen-off Fingerprint Unlock on Pixels

    December 3, 2025
    Recent Posts
    • Sony Updates PS5, PS5 Slim to Address Liquid Metal Leak Problem
    • Fire and Ash’ Closes the First ‘Avatar’ Saga
    • Google quietly restores Screen-off Fingerprint Unlock on Pixels
    • Grok would prefer a second Holocaust over harming Elon Musk
    • Google Photos 2025 Recap is here with the ability to hide unwanted faces

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 must-have-gadgets.

    Type above and press Enter to search. Press Esc to cancel.