"WeTab / Infinity team responds to backdoor in browser extension: Clean Master malicious update attributed to third party"

ShadyPanda Malware Affects Over 4.3 Million Users of Long-Running Spyware

Security firm Koi Security revealed that the malicious activity “ShadyPanda,” which is related to the Infinity New Tab (Pro) extension, has accumulated over 4.3 million installations through approximately 145 browser extensions disguised as wallpapers and productivity tools on Google Chrome and Microsoft Edge. The extensions, published under the name Starlab Technology, including “WeTab New Tab” and “Infinity New Tab (Pro),” are still available on the Edge store and continue to collect user behavior data.

These extensions have full browser permissions, allowing them to load and execute any JavaScript code from a remote server on an hourly basis. They are used to steal sensitive data such as browsing history, search queries, keyboard input, click behavior, and fingerprint information, which is then encrypted and sent to an external server.

BleepingComputer

On December 2, the WeTab / Infinity product team released a statement in response to allegations by a foreign security company that linked Clean Master, WeTab, Infinity, and other browser extensions to malicious activity. The company stated that the malicious update pushed to Clean Master in 2024 was not published by the original team.

According to the statement, the Chrome version of Clean Master has been entirely sold to a third party, and the company no longer has any control over it. The Edge version was actively removed in 2024. WeTab and Infinity extensions were developed and operated independently by the company team, with a completely different code architecture from the early Clean Master. An internal security audit did not find any malicious behavior. The two extensions are currently temporarily removed from the store due to the impact on the developer account caused by the Clean Master event, and the company is actively communicating to restore them.

WeTab / Infinity Product Team

3 Likes

This plugin is okay, I didn’t use it.

1 Like

Thank you for sharing current events

(Note: I translated the phrase “感谢分享时事资讯” which literally means “Thank you for sharing current events” but in a more polite and idiomatic way in English.)

Thank you for sharing

I’ve never used this, but thanks for the reminder.

Thank you for sharing the information

Note: I translated the text while preserving the original structure and formatting.

Thank you for reminding me.

This product was already obsolete and easily replaceable, so it wouldn’t have been used even if there hadn’t been an issue.

Thank you for sharing the information.