A widespread malware campaign has leveraged browser extensions to infect millions of users, primarily through Chrome and Edge platforms. The operation, identified as "ShadyPanda," involved at least 145 malicious extensions, some of which initially appeared legitimate but were later updated to include spyware and remote code execution capabilities. These extensions engaged in affiliate fraud, search hijacking, and exfiltration of sensitive user data, with some remaining active on the Microsoft Edge Add-ons platform despite removal from the Chrome Web Store. Attackers manipulated installation counts to boost the perceived legitimacy of their extensions, making them more likely to be trusted and installed by users.
Similar tactics have been observed in other campaigns, such as the resurgence of "Glassworm," which targets popular developer tool extensions by cloning them, inflating download statistics, and later updating them with malicious code. Attackers exploit the trust users place in well-known extensions and the difficulty in distinguishing between legitimate and malicious versions, especially within code editor marketplaces. These evolving threats highlight the ongoing risks posed by browser and code editor extensions, particularly as attackers refine their methods to evade detection and maximize impact.

Trace attribution and downstream blast radius.
11 events from the most recent confirmed update back to the earliest known activity.
Several malicious extensions reportedly remained available on the Microsoft Edge Add-ons platform until Microsoft took action after receiving the report. Microsoft then removed the identified add-ons and issued user and enterprise security guidance.
Following the researchers' findings, Google removed the identified malicious extensions from the Chrome Web Store. Reports note the takedowns occurred by the time the campaign was publicly disclosed.
On December 1, 2025, Koi Security published research attributing a seven-year browser-extension supply chain campaign to ShadyPanda, detailing its phases, infrastructure, extension IDs, and an estimated 4.3 million affected Chrome and Edge users.
Researchers described a separate Edge-focused spyware cluster, including WeTab and related extensions, that collected browsing activity, searches, clicks, fingerprints, and other telemetry and sent it to multiple domains in China. This activity was still active at the time of Koi's report.
As part of its response to the ongoing Glassworm activity, Secure Annex released an extension manager intended to help organizations inventory editor extensions and reduce exposure to malicious marketplace packages.
Several Glassworm-linked extensions with known malicious payloads were identified and removed from both the VS Marketplace and Open VSX, though some staged extensions were reportedly still manipulating download counts.
Secure Annex reported that Glassworm resurfaced in a months-long campaign targeting VS Marketplace and Open VSX with cloned developer-tool extensions that later received malicious updates. The group evolved from invisible-Unicode obfuscation to Rust-based implants and manipulated download counts to appear legitimate.
By mid-2024, previously legitimate extensions including Clean Master were updated with malicious code that polled attacker infrastructure hourly and could execute arbitrary JavaScript with full browser API access. Reporting says this backdoor phase affected roughly 300,000 users.
In early 2024, the campaign evolved to include search redirection, cookie and query exfiltration, and broader surveillance behavior through weaponized browser extensions.
Researchers linked ShadyPanda to 2023 activity in which numerous browser extensions were used for browsing-data monetization, affiliate injection, and related abuse before later escalation into more invasive capabilities.
Koi Security and follow-on reporting describe the ShadyPanda operation as starting around 2017–2018, when attackers published benign-looking Chrome and Edge extensions to build trust, installs, and positive ratings over time.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
19 references tracked. Mallory keeps watching after this page renders.
securityboulevard.com
Open sourcesecurityonline.info
Open sourcehackread.com
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourcecyberinsider.com
Open sourcelinkedin.com
Open sourcesecureannex.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.