A seven-year espionage operation by the ShadyPanda group has been uncovered, infecting over 4.3 million Chrome and Edge users through malicious browser extensions. The attackers employed a patient strategy, initially gaining trust with seemingly benign extensions before transforming them into spyware or remote code execution backdoors, highlighting a significant vulnerability in extension review processes and user trust.
Edward Kiledjian
@ekiledjian