PandaPaper turns malicious

Chrome extension modifies HTML and tries to hide it

paper panda logo with X for eyes

The “paywalling” of scientific research papers is an ongoing problem that hinders learning, hinders scientific research, and leaches profit from publicly-funded research. PaperPanda is a Chrome extension to download academic papers. Its intention is to find free links for published papers.

However what PaperPanda does under-the-hood tells another story. I’ve unearthed malicious code in PaperPanda’s Chrome extension and attempts to hide said malicious activity. This extension tried to modify my Amazon pages for unknown reasons - possibly a phisher or credit-card stealer. If you have this extension UNINSTALL IT. In this post I’ll explain how this extension is malicious and how it hides that behavior.

[Read More]