Tutorial Spot a ‘Sleeper’ Browser Ext.. It's Actually Malware Benign add-ons can be weaponized malicious updates after gaining user trust. Dec 09, 2025

Condobloke

Well-Known Member
Joined
Apr 30, 2017
Messages
13,216
Reaction score
11,145
Credits
94,857
Unfortunately, malicious extensions are usually pretending to be something else, so a quick visual check of your installed extensions may not reveal a problem. In this case, Koi Security has a list of the extension IDs associated with the ShadyPanda campaign, and you'll have to search for them one by one.
List of extensions: https://www.koi.ai/blog/4-million-b...-shadypanda-7-year-malware-campaign#heading-7
If you run Edge browser, pay attention the extensive list shown in this link

 


I shouldn't be surprised, but I am saddened that this sort of thing happens.

I am very careful to establish the credentials of any extension before I put it on, but to have it go sour years onwards might fool me.

I will be even more vigilant.

Ta for sharing, Brian.

Chris
 


Follow Linux.org

Members online

No members online now.

Top