এক ক্লিকে বুকমার্ককে নতুন ট্যাব পেজে রূপান্তর করার অভিজ্ঞতা এখনই নিন, আপনার ব্রাউজিং আরও দক্ষ করুন

Security firm Koi.ai has disclosed ShadyPanda's 7-year malware campaign, infecting over 4.3 million Chrome and Edge users, involving well-known extensions like Clean Master, WeTab, and Infinity.
Summary: Recently, security firm Koi.ai released a bombshell report exposing a threat group named ShadyPanda. Over the past 7 years, this group has infected more than 4.3 million users by distributing malicious browser extensions through Chrome and Edge stores. The report indicates that multiple well-known extensions, including Clean Master, WeTab, and Infinity, have been used as spyware to collect sensitive data such as user browsing history, search records, and even cookies.

According to Koi.ai researcher Tuval Admoni, ShadyPanda's attack activities can be traced back 7 years, with strategies continuously evolving from simple ad fraud to comprehensive browser monitoring.
Initially, ShadyPanda released 145 extensions disguised as wallpaper or productivity tools (mainly in the Edge store). These extensions profited by injecting affiliate codes (Affiliate Fraud). When users visited shopping sites like Amazon and eBay, the extensions would quietly replace links to earn commissions. Although not technically sophisticated, this gave attackers a taste of success: users trust extensions with high install counts, and app store reviews primarily focus on initial submissions.

Subsequently, attackers became bolder. Extensions represented by Infinity V+ began hijacking users' search traffic, redirecting it to known hijacking sites like trovi.com. More seriously, they started collecting users' search queries (even real-time input before users pressed Enter) and cookies from specific domains, sending the data to attackers' servers.

This phase was the most deceptive. ShadyPanda acquired or developed 5 extensions including Clean Master, allowing them to operate legitimately for years, accumulating hundreds of thousands of users, and even earning "Featured" and "Verified" badges from stores.
It wasn't until mid-2024 that attackers pushed malicious code through automatic update mechanisms. These extensions were implanted with Remote Code Execution (RCE) backdoors, downloading and executing arbitrary JavaScript code from control servers every hour. This means attackers could change extension behavior at any time, transitioning from monitoring to ransomware or credential theft.

This is currently the most impactful phase. The report indicates that 5 other extensions operated by ShadyPanda in the Edge store (including WeTab and Infinity with 3 million users) are actually powerful spyware.


These extensions are accused of collecting and exfiltrating the following data:
According to reports, this data was sent to servers located in China as well as Google Analytics.

This incident has sparked strong reactions across major tech communities. Many long-term users expressed shock and anger, while others began searching for alternatives.
In the Linux.do community, users expressed concerns about data breaches:
"I spent so long customizing everything, and now it's all gone! Malicious plugins I**" —— Acheron "I've been using wetab for so long, immediately uninstalled and switched to itab" —— Cknight "Got hit, don't know what exactly was stolen" —— hjie
On V2EX, users also posted:
"Can't laugh about this, been using Infinity new tab page for years, suspected to be poisoned"
Users in the NodeLoc community expressed relief at not being affected and reminded each other to stay vigilant about security.
These authentic voices reflect users' concern for privacy and security, as well as disappointment at being "backstabbed" by tools they once trusted.
The report provides detailed analysis of ShadyPanda's technical methods:
api.extensionplay[.]com, downloading and executing obfuscated JavaScript code.In response to Koi.ai's allegations, the WeTab and Infinity teams quickly released response statements (see Official Statement).
The teams stated:
Regardless of the facts, browser extension security risks always exist. Security experts recommend:
Currently, Microsoft Edge and Chrome stores have removed some of the involved extensions, but according to the report, some extensions are still accessible in the Edge store. Users should remain vigilant and decide whether to continue using related products based on their own judgment.
Reference sources: Koi.ai Blog, BleepingComputer, V2EX Discussion