ShadyPanda Malware Patiently Spread Across Edge And Chrome Web Store For Years Before Activating
Sleeper Apps Awakened
ShadyPanda is a nasty project that has been running invisibly for years only to attempt to unleash devastation this year. The group behind it has been publishing useful apps to both the Chrome Web Store and the Edge marketplace, some apps gaining Featured and Verified status on those platforms. The apps were handy tools which were downloaded millions of times and got many great reviews on both stores. The group behind ShadyPanda was even nice enough to keep those apps updated as new versions of the browsers came out and bugs were discovered.
Unfortunately this was all in the name of evil, as they then released an update to those apps heavily laden with a variety of malware. The apps, if they got that update started to surveil everything, “checking api.extensionplay[.]com for new instructions every hour, downloading arbitrary JavaScript, and executing it with full browser API access. It can also inject malicious content into any website, including HTTPS connections.” This let them watch you browse in real time, or just collect logs to upload.
The malware was also bright enough to detect if a user fired up any development tools, and if they did the apps reverted back to their innocent versions until there was no risk of detection. Chrome checks all updates to apps on their store, and managed to catch what ShadyPanda was up to relatively quickly but not before some machines were infected. It took until this week before those apps disappeared from the Edge Add-on store.
If one of your favourite apps just disappeared from your browser, you might want to make sure to do a few scans of your machine!
The attackers, which Koi named ShadyPanda, played the long game: publishing legitimate extensions, accumulating thousands or sometimes millions of downloads over several years, and then pushing a malware-laden update that auto updates across the entire user base.
More Tech News From Around The Web
- Microsoft “mitigates” Windows LNK flaw exploited as zero-day @ Bleeping Computer
- Google fixes two Android zero days exploited in attacks, 107 flaws @ Bleeping Computer
- Microsoft appears to move on from its most loyal ‘customers’ – Contoso and Fabrikam @ The Register
- Windows 11 Growth Slows As Millions Stick With Windows 10 @ Slashdot
- Syntax hacking: Researchers discover sentence structure can bypass AI safety rules @ Ars Technica
- Google’s Vibe Coding Platform Deletes Entire Drive @ Slashdot
- HPE brings Juniper Networking into its AMD Helios Rack-Scale AI Orbit @ ServeTheHome
- NVIDIA NVLink Fusion Tapped for Future AWS Trainium4 Deployments @ ServeTheHome
- India orders device makers to put government-run security app on all phones @ Ars Technica
- Samsung Debuts Its First Trifold Phone @ Slashdot
- Guitar amp sims have gotten astonishingly good @ Ars Technica
- ASUS ZenWiFi BQ16 review: Quad Band Mesh with Wi-Fi 7 @ KitGuru


