logoalt Hacker News

4.3M Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign

72 pointsby janpiotoday at 4:30 PM15 commentsview on HN

Comments

huydotnettoday at 7:12 PM

I came to the article hoping to see the list of affected extensions, so I can check if I ever installed any of them. All I get was a list of extension ID at the very bottom of the post. Is this some sort of security practice to not promoting malicious packages or something?

show 2 replies
payphonefiendtoday at 6:31 PM

Painful read, this reads like it was written by AI.

show 6 replies
gudzpoztoday at 6:46 PM

The WeTab / Infinity team has responded to this [1] (in Chinese). Basically, they argue that:

- The Clean Master extension has long been sold, and the malicious updated was not pushed by them.

- The other two mentioned extensions are not at all malicious. They collect use info for extension opt-out-able features and analytics (using Google Analytics and Baidu Analytics).

- They are communicating with the extension stores to restore their extension.

Let's hope it's not an AI company making AI-generated accusations.

[1] https://mp.weixin.qq.com/s/E8YQLWZFM2J7r5DZNSl47w & https://www.v2ex.com/t/1176484

show 1 reply
ipnontoday at 6:14 PM

The builtin JavaScript interpreter is such a devious touch. No one blinks an eye at several MBs of extension data. That’s plenty of room to store arbitrary runtimes in, and then all the default browser runtime protections are pointless.

show 1 reply
badmonstertoday at 7:08 PM

Browser extensions are a fascinating attack vector because users grant them extraordinary privileges without understanding the risk. The 7-year persistence here is notable - malware that stays undetected that long usually means good operational security and slow, careful changes that don't trigger alarms.

show 1 reply