Stealthy browser extensions waited years before infecting 4.3M Chrome, Edge users with backdoors and spyware - "No phishing. No social engineering. Just trusted extensions with quiet version bumps that turned productivity tools into surveillance platforms,"

A seven-year malicious browser extension campaign infected 4.3 million Google Chrome and Microsoft Edge users with malware, including backdoors and spyware sending people's data to servers in China. And, according to Koi researchers, five of the extensions with more than 4 million installs are still live in the Edge marketplace.

The attackers, which Koi named ShadyPanda, played the long game: publishing legitimate extensions, accumulating thousands or sometimes millions of downloads over several years, and then pushing a malware-laden update that auto updates across the entire user base.

Because both marketplaces review extensions upon submission – it's not an ongoing process – these seemingly stellar productivity tools, some with Featured and Verified status alongside glowing user reviews and high install counts, were allowed to track people's behavior and steal sensitive info silently for years.

"No phishing. No social engineering. Just trusted extensions with quiet version bumps that turned productivity tools into surveillance platforms," the threat hunting team said in a Monday blog.

Microsoft did not respond to The Register's requests for comment. A Google spokesperson confirmed none of the extensions are available on the Chrome Web Store, and we are aware that Google screens every single update to extensions in the Chrome store, no matter how minor the change.

Koi tracked ShadyPanda's activity in multiple phases, and says two campaigns are still active.

One of these campaigns included five extensions that infected 300,000 users with a remote-code-execution enabling backdoor. Three of the five were uploaded between 2018 and 2019 and achieved Featured and Verified status. One of those extensions, called Clean Master and published by Starlab Technology, has more than 200,000 installs.

In mid-2024, after being downloaded more than 300,000 times, ShadyPanda pushed a malicious update containing a backdoor across all five running on Chrome and Edge. While the extensions have since been removed from both marketplaces, "the infrastructure for full-scale attacks remains deployed on all infected browsers," the researchers wrote.

The malware allows complete browser surveillance, checking api.extensionplay[.]com for new instructions every hour, downloading arbitrary JavaScript, and executing it with full browser API access. It can also inject malicious content into any website, including HTTPS connections.

Clean Master then sends all of this stolen data - every URL visited, HTTP referrers showing navigation patterns, timestamps for activity profiling, persistent UUID4 identifiers, and complete browser fingerprints - to ShadyPanda-controlled servers.

Plus, the malware contains anti-analysis capabilities and switches to benign behavior if a researcher opens developer tools.

An additional five extensions from the same publisher launched on Edge around 2023 and now have more than four million combined installs. According to Koi, all five are still live on the Edge marketplace, and two of these install spyware on users' machines.

One of these five, WeTab, has three million installs. It's a surveillance platform disguised as a productivity tool that snarfs all sorts of user data: every URL visited, search queries, mouse-click tracking, browser fingerprinting, page interaction data, and storage access – and then sends all of this, in real time, to 17 different domains (8 Baidu servers in China, 7 WeTab servers in China, and Google Analytics).

"The extension already has dangerous permissions including access to all URLs and cookies, users are downloading them right now," the researchers wrote. "ShadyPanda can push updates at any time, weaponizing 4 million browsers with the same RCE backdoor framework [from Clean Master] or something even worse."

Koi also traced ShadyPanda to a couple of earlier, now inactive, campaigns. One of these, which occurred during 2023, included 20 Chrome Web Store extensions and 125 on Microsoft Edge, all disguised as wallpaper or productivity apps.

This one worked by silently tracking and monetizing users' browsing data. When someone clicked on eBay, Amazon, or Booking.com, the extensions injected affiliate tracking codes and Google Analytics trackers, which were then logged and used to sell people's website visits and search queries.

A second inactive campaign from early 2023 was also disguised as a new tab productivity tool called Infinity V+. It redirected every user's search to browser hijacking website trovi.com, exfiltrated cookies, and logged users' keystrokes in the search box, sending all of this info to external servers.

According to the researchers, all of these ShadyPanda campaigns illustrate a problem in the way marketplaces manage extensions. "They don't watch what happens after approval," they wrote.

Article Link

Archive
 
They don’t name all the extensions so people can check if they have them and remove them? Curious.
Here are a few of the extensions as far as I could find from the original report:

WeTab 新标签页 (WeTab New Tab Page)
CleanMaster
Infinity V+

Seems like there are a couple hundred potentially compromised apps, but even some of the bigger ones getting mentioned would have justified this article. The Koi report I linked above also has some indicators of compromise that the more tech savvy can use to hopefully double check their extensions. The report does not systematically list every compromised extension, and it seems as though a lot of them are deprecated at this point, though obviously it's hard to check that without more info.
 
They don’t name all the extensions so people can check if they have them and remove them? Curious.
I looked at several articles and one links to the report, with a list of domains and apps at the bottom, but it looks like gibberish to me.

C&C Domains:

extensionplay[.]com
yearnnewtab[.]com
api.cgatgpt[.]net

Exfiltrations Domains:

dergoodting[.]com
yearnnewtab[.]com
cleanmasters[.]store
s-85283.gotocdn[.]com
s-82923.gotocdn[.]com

Chrome Extensions:

eagiakjmjnblliacokhcalebgnhellfi
ibiejjpajlfljcgjndbonclhcbdcamai
ogjneoecnllmjcegcfpaamfpbiaaiekh
jbnopeoocgbmnochaadfnhiiimfpbpmf
cdgonefipacceedbkflolomdegncceid
gipnpcencdgljnaecpekokmpgnhgpela
bpgaffohfacaamplbbojgbiicfgedmoi
ineempkjpmbdejmdgienaphomigjjiej
nnnklgkfdfbdijeeglhjfleaoagiagig
Mljmfnkjmcdmongjnnnbbnajjdbojoci
llkncpcdceadgibhbedecmkencokjajg
nmfbniajnpceakchicdhfofoejhgjefb
ijcpbhmpbaafndchbjdjchogaogelnjl
olaahjgjlhoehkpemnfognpgmkbedodk
gnhgdhlkojnlgljamagoigaabdmfhfeg
cihbmmokhmieaidfgamioabhhkggnehm
lehjnmndiohfaphecnjhopgookigekdk
hlcjkaoneihodfmonjnlnnfpdcopgfjk
hmhifpbclhgklaaepgbabgcpfgidkoei
lnlononncfdnhdfmgpkdfoibmfdehfoj
nagbiboibhbjbclhcigklajjdefaiidc
ofkopmlicnffaiiabnmnaajaimmenkjn
ocffbdeldlbilgegmifiakciiicnoaeo
eaokmbopbenbmgegkmoiogmpejlaikea
lhiehjmkpbhhkfapacaiheolgejcifgd
ondhgmkgppbdnogfiglikgpdkmkaiggk
imdgpklnabbkghcbhmkbjbhcomnfdige

Edge Add-ons:

bpelnogcookhocnaokfpoeinibimbeff
enkihkfondbngohnmlefmobdgkpmejha
hajlmbnnniemimmaehcefkamdadpjlfa
aadnmeanpbokjjahcnikajejglihibpd
ipnidmjhnoipibbinllilgeohohehabl
fnnigcfbmghcefaboigkhfimeolhhbcp
nlcebdoehkdiojeahkofcfnolkleembf
fhababnomjcnhmobbemagohkldaeicad
nokknhlkpdfppefncfkdebhgfpfilieo
ljmcneongnlaecabgneiippeacdoimaa
onifebiiejdjncjpjnojlebibonmnhog
dbagndmcddecodlmnlcmhheicgkaglpk
fmgfcpjmmapcjlknncjgmbolgaecngfo
kgmlodoegkmpfkbepkfhgeldidodgohd
hegpgapbnfiibpbkanjemgmdpmmlecbc
gkanlgbbnncfafkhlchnadcopcgjkfli
oghgaghnofhhoolfneepjneedejcpiic
fcidgbgogbfdcgijkcfdjcagmhcelpbc
nnceocbiolncfljcmajijmeakcdlffnh
domfmjgbmkckapepjahpedlpdedmckbj
cbkogccidanmoaicgphipbdofakomlak
bmlifknbfonkgphkpmkeoahgbhbdhebh
ghaggkcfafofhcfppignflhlocmcfimd
hfeialplaojonefabmojhobdmghnjkmf
boiciofdokedkpmopjnghpkgdakmcpmb
ibfpbjfnpcgmiggfildbcngccoomddmj
idjhfmgaddmdojcfmhcjnnbhnhbmhipd
jhgfinhjcamijjoikplacnfknpchndgb
cgjgmbppcoolfkbkjhoogdpkboohhgel
afooldonhjnhddgnfahlepchipjennab
fkbcbgffcclobgbombinljckbelhnpif
fpokgjmlcemklhmilomcljolhnbaaajk
hadkldcldaanpomhhllacdmglkoepaed
iedkeilnpbkeecjpmkelnglnjpnacnlh
hjfmkkelabjoojjmjljidocklbibphgl
dhjmmcjnajkpnbnbpagglbbfpbacoffm
cgehahdmoijenmnhinajnojmmlnipckl
fjigdpmfeomndepihcinokhcphdojepm
chmcepembfffejphepoongapnlchjgil
googojfbnbhbbnpfpdnffnklipgifngn
fodcokjckpkfpegbekkiallamhedahjd
igiakpjhacibmaichhgbagdkjmjbnanl
omkjakddaeljdfgekdjebbbiboljnalk
llilhpmmhicmiaoancaafdgganakopfg
nemkiffjklgaooligallbpmhdmmhepll
papedehkgfhnagdiempdbhlgcnioofnd
glfddenhiaacfmhoiebfeljnfkkkmbjb
pkjfghocapckmendmgdmppjccbplccbg
gbcjipmcpedgndgdnfofbhgnkmghoamm
ncapkionddmdmfocnjfcfpnimepibggf
klggeioacnkkpdcnapgcoicnblliidmf
klgjbnheihgnmimajhohfcldhfpjnahe
acogeoajdpgplfhidldckbjkkpgeebod
ekndlocgcngbpebppapnpalpjfnkoffh
elckfehnjdbghpoheamjffpdbbogjhie
dmpceopfiajfdnoiebfankfoabfehdpn
gpolcigkhldaighngmmmcjldkkiaonbg
dfakjobhimnibdmkbgpkijoihplhcnil
hbghbdhfibifdgnbpaogepnkekonkdgc
fppchnhginnfabgenhihpncnphhafmac
ghhddclfklljabeodmcejjjlhoaaiban
bppelgkcnhfkicolffhlkbdghdnjdkhi
ikgaleggljchgbihlaanjbkekmmgccam
bdhjinjoglaijpffoamhhnhooeimgoap
fjioinpkgmlcioajfnncgldldcnabffe
opncjjhgbllenobgbfjbblhghmdpmpbj
cbijiaccpnkbdpgbmiiipedpepbhioel
fbbmnieefocnacnecccgmedmcbhlkcpm
hmbacpfgehmmoloinfmkgkpjoagiogai
paghkadkhiladedijgodgghaajppmpcg
bafbmfpfepdlgnfkgfbobplkkaoakjcl
kcpkoopmfjhdpgjohcbgkbjpmbjmhgoi
jelgelidmodjpmohbapbghdgcpncahki
lfgakdlafdenmaikccbojgcofkkhmolj
hdfknlljfbdfjdjhfgoonpphpigjjjak
kpfbijpdidioaomoecdbfaodhajbcjfl
fckphkcbpgmappcgnfieaacjbknhkhin
lhfdakoonenpbggbeephofdlflloghhi
ljjngehkphcdnnapgciajcdbcpgmpknc
ejfocpkjndmkbloiobcdhkkoeekcpkik
ccdimkoieijdbgdlkfjjfncmihmlpanj
agdlpnhabjfcbeiempefhpgikapcapjb
mddfnhdadbofiifdebeiegecchpkbgdb
alknmfpopohfpdpafdmobclioihdkhjh
hlglicejgohbanllnmnjllajhmnhjjel
iaccapfapbjahnhcmkgjjonlccbhdpjl
ehmnkbambjnodfbjcebjffilahbfjdml
ngbfciefgjgijkkmpalnmhikoojilkob
laholcgeblfbgdhkbiidbpiofdcbpeeo
njoedigapanaggiabjafnaklppphempm
fomlombffdkflbliepgpgcnagolnegjn
jpoofbjomdefajdjcimmaoildecebkjc
nhdiopbebcklbkpfnhipecgfhdhdbfhb
gdnhikbabcflemolpeaaknnieodgpiie
bbdioggpbhhodagchciaeaggdponnhpa
ikajognfijokhbgjdhgpemljgcjclpmn
lmnjiioclbjphkggicmldippjojgmldk
ffgihbmcfcihmpbegcfdkmafaplheknk
lgnjdldkappogbkljaiedgogobcgemch
hiodlpcelfelhpinhgngoopbmclcaghd
mnophppbmlnlfobakddidbcgcjakipin
jbajdpebknffiaenkdhopebkolgdlfaf
ejdihbblcbdfobabjfebfjfopenohbjb
ikkoanocgpdmmiamnkogipbpdpckcahn
ileojfedpkdbkcchpnghhaebfoimamop
akialmafcdmkelghnomeneinkcllnoih
eholblediahnodlgigdkdhkkpmbiafoj
ipokalojgdmhfpagmhnjokidnpjfnfik
hdpmmcmblgbkllldbccfdejchjlpochf
iphacjobmeoknlhenjfiilbkddgaljad
jiiggekklbbojgfmdenimcdkmidnfofl
gkhggnaplpjkghjjcmpmnmidjndojpcn
opakkgodhhongnhbdkgjgdlcbknacpaa
nkjomoafjgemogbdkhledkoeaflnmgfi
ebileebbekdcpfjlekjapgmbgpfigled
oaacndacaoelmkhfilennooagoelpjop
ljkgnegaajfacghepjiajibgdpfmcfip
hgolomhkdcpmbgckhebdhdknaemlbbaa
bboeoilakaofjkdmekpgeigieokkpgfn
dkkpollfhjoiapcenojlmgempmjekcla
emiocjgakibimbopobplmfldkldhhiad
nchdmembkfgkejljapneliogidkchiop
lljplndkobdgkjilfmfiefpldkhkhbbd
hofaaigdagglolgiefkbencchnekjejl
hohobnhiiohgcipklpncfmjkjpmejjni
jocnjcakendmllafpmjailfnlndaaklf
bjdclfjlhgcdcpjhmhfggkkfacipilai
ahebpkbnckhgjmndfjejibjjahjdlhdb
enaigkcpmpohpbokbfllbkijmllmpafm
bpngofombcjloljkoafhmpcjclkekfbh
cacbflgkiidgcekflfgdnjdnaalfmkob
ibmgdfenfldppaodbahpgcoebmmkdbac
 
Browsers are full of precious information and stores are not keeping up with the times, if anything it's just as bad as it was before the webexts locking down for "muh security". I think it's also one of the worst places you want the "auto-update by default" settings browsers default to. Developers will get dozens of email every month from shady people trying to purchase them and cram them full of tracking spyware, and/or will get their keys compromised.

If you had those installed through the store, chances are their signatures have been revoked and most browsers will block or remove them on the first startup, but you're waiting for Google/M$/Moz to do the needful, and they were incompetent enough to let them pass in the first place. Friendly reminder you can unpack them and either check the source code yourself or defer it to a random LLM of choice just for extra safety, if you need it. It's usually very obvious when something's up with them.

but it looks like gibberish to me.
It's not the extension names but the unique identifier of the extension version. You can find those, for chromium, in paths like:
Default/DNR Extension Rules/<ID>/
Default/Managed Extension Settings/<ID>/
Default/Local Extension Settings/<ID>/
Default/Extensions/<ID>/
It's fucking annoying how they never include those, I saw the article title and knew they wouldn't have a comprehensive list. Someone's going to try and make one soon enough, for now it seems at least those were affected;
  • Clean Master: the best Chrome Cache Cleaner
  • Speedtest Pro-Free Online Internet Speed Test
  • BlockSite
  • Address bar search engine switcher
  • SafeSwift New Tab
  • Infinity V+ New Tab
  • OneTab Plus:Tab Manage & Productivity
  • WeTab 新标签页
  • Infinity New Tab for Mobile
  • Infinity New Tab (Pro)
  • Infinity New Tab
  • Dream Afar New Tab
  • Download Manager Pro
  • Galaxy Theme Wallpaper HD 4k HomePage
  • Halo 4K Wallpaper HD HomePage
 
What retard writes an article about rugpull/supply chain malware attacks and doesn’t tell you what got attacked?


> Jessica Lyons

1764905310983.png

Oh.
 
I always get nervous installing mods, emulators etc with an automatic update or phone home feature because of shit like this. Too many stories about mod authors losing their shit over politics or whatever and going off the deep end. I don't want some tranny to have a backdoor into my system just because I needed his autistic programming knowledge to get a Playstation 3 controller to work on PC.
 
  • Clean Master: the best Chrome Cache Cleaner
  • Speedtest Pro-Free Online Internet Speed Test
  • BlockSite
  • Address bar search engine switcher
  • SafeSwift New Tab
  • Infinity V+ New Tab
  • OneTab Plus:Tab Manage & Productivity
  • WeTab 新标签页
  • Infinity New Tab for Mobile
  • Infinity New Tab (Pro)
  • Infinity New Tab
  • Dream Afar New Tab
  • Download Manager Pro
  • Galaxy Theme Wallpaper HD 4k HomePage
  • Halo 4K Wallpaper HD HomePage
This is going to sound condescending but this is a genuine question. How do these ever get any traction? Nearly all of these scream "scam" to me from the name alone. "4K" in the name? scam. "Master" in the name? scam. "Infinity"? That's a scam. Over literal name in engrish? Believe it or not, also a scam! Is your extension "Pro"? Scammed again.

Honestly the only ones that aren't blatant from the name alone are "WeTab", "BlockSite", and "OneTab Plus" (if the name doesn't include the whole thing). And I'm not trying to say I'm some galaxy brain here just that any name that is trying too hard to say the extension is legitimate/high quality is incredibly suspect.
 
Última edición:
How do these ever get any traction? Nearly all of these scream "scam" to me from the name alone.
Yeah, Common Sense 2025 Edition would work fine against those. It's just my own hypothesis with nothing to back it up, but considering there's no "quick" way to install unauthorized, unsigned extensions outside those stores on the kind of browser versions you find in most PCs (and business ones slacking off with their group policies), I suspect at least some of those aren't supposed to be accidentally stumbled upon by a clueless user, but rather installed by somebody that briefly had local access or whatever and it has to go through them. Some others are definitely sold off or compromised, and maybe casting a wide net with low effort, fake extensions really might work if some keep doing it.
 
Atrás
Top Abajo