HomeSecurityChrome: QuickLens extension steals data and crypto

Chrome: QuickLens extension steals data and crypto

A seemingly innocent extension for Google’s Chrome browser has turned into a serious threat to thousands of users. “QuickLens – Search Screen with Google Lens” has been removed from the Chrome Web Storeafter it was found to have been compromised and used to distribute malware and steal cryptocurrency. The case highlights once again how vulnerable the browser extension ecosystem can be, even when it comes to tools that carry trust ratings.

Chrome Extension QuickLens

From a useful tool to an attack vehicle

QuickLens started as a practical solution for those who wanted direct access to Google Lens through Chrome. In a short time, it reached about 7,000 users, and at one point even received a relevant badge from Google, an element that strengthened its credibility in the eyes of the public.

See also: How AI reduces or amplifies errors in cybersecurity

However, on February 17, 2026 version 5.8, which contained malicious scripts. The update introduced ClickFix attacks and information theft mechanisms, turning the extension into a digital espionage tool. Users who proceeded with the automatic upgrade found themselves exposed without knowing it.

Change of ownership and suspicious movements in the background

Annex researchers revealed that shortly before the release of the malicious version, the extension had changed ownership through the ExtensionHub platform , which sells ready-made browser extension projects. On February 1, 2026, the new owner appeared with the email address support@doodlebuggle.top and the company name “ LLC Quick Lens ”, accompanied by a new privacy policy on a newly created domain.

Just two weeks later, the suspicious update was pushed out to users. The speed of the developments demonstrates an organized plan, aimed at massively exploiting the already established user base.

Chrome: QuickLens extension steals data and crypto

QuickLens: How security mechanisms were bypassed

Version 5.8 requested additional permissions, such as declarativeNetRequestWithHostAccess and webRequest, gaining increased control over browser traffic. At the same time, it incorporated a rules.json file that removed critical security headers, including Content-Security-Policy (CSP), X-Frame-Options, and X-XSS-Protection. In simple terms, it disabled basic defenses for websites against malicious code.

See also: 10 simple ways to protect your personal data in 2026

The extension communicated with a command-and-control (C2) server at api.extensionanalyticspro[.]top, generating a permanent UUID for each victim and collecting information about country, browser, and operating system. Every five minutes, it requested new commands, turning the browser into a remote "agent."

BleepingComputer reported that users on Reddit were complaining about fake Google Update notifications appearing on every page. The malicious payload was loaded via a “1×1 GIF pixel” technique, executing JavaScript even on websites that would normally block it.

ClickFix, PowerShell and targeted cryptocurrency theft

The first stage led to a fake Google update, which prompted the user to run code for “verification”. On Microsoft Windows systems, it resulted in the download of a file googleupdate.exe, signed with a company certificate in China. Once executed, a hidden PowerShell command that communicated with a second server using a custom user-agent “Katzilla”.

Meanwhile, another JavaScript agent targeted crypto wallets such as MetaMask, Phantom, Coinbase Wallet, Trust Wallet, and Exodus, attempting to extract seed phrases and credentials. Additional payloads targeted Gmail inboxes, Facebook Business Manager data, and YouTube channel information. There were also claims of the AMOS infostealer being distributed on macOS, without full confirmation.

See also: Malicious Go Crypto Module steals passwords and installs Rekoobe Backdoor

Chrome: QuickLens extension steals data and crypto

Reaction and protection instructions

Google has removed the extension and Chrome is automatically disabling it. However, users who installed it are urged to completely delete, scan for malware, change all saved passwords , and transfer crypto assets to new wallets.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This is not an isolated incident. Recently, Huntress uncovered an extension that intentionally corrupted browsers and offered fake fixes by installing ModeloRAT. The message is clear: even a well-reviewed tool can turn into an attack vehicle within days, confirming that vigilance remains the strongest defense.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS