


Perceptive Security
SOC/SIEM Consultancy

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware
Published:
1 december 2025 om 17:29:00
Alert date:
5 december 2025 om 08:03:23
Source:
thehackernews.com

ShadyPanda threat actor conducted a seven-year browser extension campaign affecting over 4.3 million installations. Five legitimate extensions were compromised with malicious changes in mid-2024, gaining 300,000 installs. The extensions turned popular browser tools into spyware before being taken down. This represents a significant supply chain attack targeting browser users through compromised extensions. The campaign demonstrates the threat of legitimate software being weaponized for malicious purposes.
Technical details
Mitigation steps:
Affected products:
Browser Extensions
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.