A seven-year malicious browser extension campaign infected 4.3 million Google Chrome and Microsoft Edge users with malware, including backdoors and spyware sending people's data to servers in China. And, according to Koi researchers, five of the extensions with more than 4 million installs are still live in the Edge marketplace. The attackers, which Koi named ShadyPanda, played the long game: publishing legitimate extensions, accumulating thousands or sometimes millions of downloads over several years, and then pushing a malware-laden update that auto updates across the entire user base. Because both marketplaces review extensions upon submission – it's not an ongoing process – these seemingly stellar productivity tools, some with Featured and Verified status alongside glowing user reviews and high install counts, were allowed to track people's behavior and steal sensitive info silently for years. "No phishing. No social engineering. Just trusted extensions with quiet version bumps that turned productivity tools into surveillance platforms," the threat hunting team said in a Monday blog. Microsoft did not respond to The Register's requests for comment. A Google spokesperson confirmed none of the extensions are available on the Chrome Web Store, and we are aware that Google screens every single update to extensions in the Chrome store, no matter how minor the change. Koi tracked ShadyPanda's activity in multiple phases, and says two campaigns are still active. One of these cam...
Browser extensions pushed malware to 4.3M Chrome, Edge users
The Register
·Jessica Lyons
·Published Dec 1, 2025
·Updated
Affected Software
2 affected components
Google Chrome
Microsoft Edge
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a seven-year campaign of malicious browser extensions that infected 4.3 million users of Google Chrome and Microsoft Edge.
2
What security implications are discussed in the article?
The article highlights the risks of malware, including backdoors and spyware, that compromise user data and privacy.
3
What products or software are affected by the malware campaign?
The affected products are Google Chrome and Microsoft Edge browsers.
4
How many users were impacted by the malicious browser extensions?
The campaign infected approximately 4.3 million users.
5
Where were the user data from the spyware being sent to?
The spyware was sending user data to servers located in China.