CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

QuickLens Chrome Extension Compromised to Steal Cryptocurrency and Credentials

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

The QuickLens Chrome extension, initially a legitimate tool for Google Lens searches, was compromised to push malware and steal cryptocurrency and credentials from approximately 7,000 users. The malicious version 5.8, released on February 17, 2026, introduced ClickFix attacks and info-stealing functionality. The extension was removed from the Chrome Web Store by Google after the discovery. The compromised extension stripped browser security headers, communicated with a command-and-control (C2) server, and executed malicious JavaScript scripts on every page load. It targeted various cryptocurrency wallets, login credentials, payment information, and sensitive form data. Users are advised to remove the extension, scan their devices for malware, and reset passwords.

Timeline

  1. 28.02.2026 21:18 1 articles · 3h ago

    QuickLens Chrome Extension Compromised to Steal Cryptocurrency and Credentials

    On February 17, 2026, a malicious version 5.8 of the QuickLens Chrome extension was released, introducing ClickFix attacks and info-stealing functionality. The extension stripped browser security headers, communicated with a C2 server, and executed malicious JavaScript scripts on every page load. It targeted various cryptocurrency wallets, login credentials, payment information, and sensitive form data. Google has removed the extension from the Chrome Web Store and automatically disables it for affected users.

    Show sources

Information Snippets