QuickLens Chrome Extension Compromised to Steal Cryptocurrency and Credentials
Updated:
· First: 28.02.2026 21:18
· 📰 1 src / 1 articles
The QuickLens Chrome extension, initially a legitimate tool for Google Lens searches, was compromised to push malware and steal cryptocurrency and credentials from approximately 7,000 users. The malicious version 5.8, released on February 17, 2026, introduced ClickFix attacks and info-stealing functionality. The extension was removed from the Chrome Web Store by Google after the discovery. The compromised extension stripped browser security headers, communicated with a command-and-control (C2) server, and executed malicious JavaScript scripts on every page load. It targeted various cryptocurrency wallets, login credentials, payment information, and sensitive form data. Users are advised to remove the extension, scan their devices for malware, and reset passwords.