63SATS
ShadyPanda’s Silent Takeover: Browser Extensions Used as Stealth Surveillance ToolsAttributed to - Mr Neehar Pathare, MD, CEO & CIO, 63SATS Cybertech
Cybersecurity News

ShadyPanda’s Silent Takeover: Browser Extensions Used as Stealth Surveillance ToolsAttributed to - Mr Neehar Pathare, MD, CEO & CIO, 63SATS Cybertech

Dec 18, 2025|2 MinlogoBy 63SATS

Summarize this blog with :


ShadyPanda, a threat group associated with Chinese-based cyber-surveillance activity, has been identified as hijacking legitimate Chrome and Edge browser extensions to turn them into spyware tools for stealing user data. According to The Hacker News, multiple browser extensions with more than 4.3 million total installs were found harvesting sensitive browsing information and exfiltrating it to remote servers controlled by the attackers.This blog summarizes what happened, who’s believed to be behind it, and how organizations can respond.

The scale of this incident reveals how browser extensions often granted deep access permissions are becoming silent spyware vectors targeting unsuspecting users across corporate, academic, and consumer environments.What Happened?

Affected Platforms & Extensions

Why This Matters

Why it’s particularly dangerous

Government & Industry response

The disclosure and active exploitation of the malicious extension grab an immediate and coordinated response from both government and industry:

  • Google removed the malicious extensions from the Chrome Web Store upon verification of malicious activity.

  • Microsoft began disabling the extensions across Edge installations and rolled out warnings to enterprise administrators.

  • Cybersecurity advisory groups and CERT teams issued warnings recommending enterprises audit browser-extension usage.

  • Analysts investigating Chinese-linked cyber capabilities point to an expanding network of front organizations used for digital infiltration and surveillance.

How Organizations Can RespondTo mitigate the risks posed by this critical vulnerablity, organizations should consider the following measures:

Final Word

The ShadyPanda extension campaign proves that users don’t need to download malware — they install it themselves through the browser store. These extensions slip under the radar and quietly siphon data, blending into legitimate user activity.With attackers increasingly shifting to browser-layer espionage, organizations must adopt a proactive extension-governance policy, enforce strict permission controls, and continuously monitor browser-level telemetry.“Small extension, big exposure”References1. ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spywarehttps://thehackernews.com/2025/12/shadypanda-turns-popular-browser.html2. ShadyPanda browser extensions amass 4.3M installs in malicious campaignhttps://www.bleepingcomputer.com/news/security/shadypanda-browser-extensions-amass-43m-installs-in-malicious-campaign/3. 4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaignhttps://cybersecuritynews.com/4-3-million-chrome-and-edge-users-hacked/

banner

Experience Our Solutions in Action

Explore interactive demos and see how 63SATS helps you stay ahead of evolving cyber threats.

Share this post


ShadyPanda’s Silent Takeover: Browser Extensions Used as Stealth Surveillance ToolsAttributed to - Mr Neehar Pathare, MD, CEO & CIO, 63SATS Cybertech | 63SATS Blogs