Malicious Browser Extensions Infect 4.3M Users with Spyware

Malicious Browser Extensions Infect 4.3M Users with Spyware

First seen 1 Dec 2025, 20:43 UTC ThehackernewsTheregisterRedhotcyberInfosecurity-MagazineCsoonline+6 82% similarity 44.0

Article Content

Browse articles
ThreatCluster

A seven-year campaign involving malicious browser extensions has infected 4.3 million Google Chrome and Microsoft Edge users with malware, including backdoors and spyware that transmit data to servers in China. The attackers, identified as ShadyPanda, published seemingly legitimate extensions, amassing millions of downloads before deploying the malware. Notably, five of these extensions remain active in the Edge marketplace.

ThreatCluster AI

Community

Browse all →