Two popular Chrome extensions, QuickLens and ShotBird, were turned into malicious tools after a change of ownership, allowing attackers to distribute malware, inject arbitrary code, and steal sensitive data from thousands of users.
See also: Chrome: QuickLens extension steals data and crypto

The Chrome extensions were originally linked to a developer named “akshayanuonline@gmail.com” (BuildMelon). QuickLens – Search Screen with Google Lens had amassed 7,000 users, while ShotBird – Scrolling Screenshots, Tweet Images & Editor had 800 users. While QuickLens is no longer available for download from the Chrome Web Store, ShotBird is still accessible.
According to research published by monxresearch-sec, ShotBird was originally released in November 2024, with its developer, Akshay Anu S, claiming to X that the extension is suitable for “creating professional, studio-like visuals” and that all editing is done locally. The browser add-on was flagged as “Featured” in January 2025, before being transferred to a different developer (“loraprice198865@gmail.com”) sometime last month.
Similarly, QuickLens was listed for sale on ExtensionHub on October 11, 2025, by “akshayanuonline@gmail.com” just two days after it was published, as reported by John Tuckner of Annex Security. On February 1, 2026, the extension’s owner changed to “support@doodlebuggle.top” on the Chrome Web Store listing page.
Technical details of the malicious update
The malicious update introduced to QuickLens on February 17, 2026, retained the original functionality but introduced the ability to strip security headers from every HTTP response. This allows malicious scripts inserted into a website to make arbitrary requests to other domains, bypassing Content Security Policy (CSP) protections.
See also: Google fixes 10 serious vulnerabilities in Chrome

Additionally, the extension contained code for fingerprinting the user's country, detecting the browser and operating system, and polling an external server every five minutes to download JavaScript, which is stored in the browser's local storage and executed on every page load by adding a hidden 1×1 GIF element and setting the JavaScript string as its "onload" attribute.
A similar analysis of the ShotBird extension by monxresearch-sec revealed the use of direct callbacks to deliver JavaScript code instead of creating a 1×1 pixel image to trigger execution. The JavaScript is designed to display a fake Google Chrome browser update prompt, clicking on which users are served a ClickFix-style page to open the Windows Run dialog, launch “cmd.exe” and paste a PowerShell command, resulting in the download of an executable file named “googleupdate.exe” on Windows hosts.
Researchers believe the same hacker is behind the breach of both extensions and is running such add-ons in parallel. This tactic represents an evolving threat in the Chrome extensions ecosystem, where malicious actors are purchasing legitimate extensions with an installed user base and turning them into malware distributors.
See also: Chrome Vulnerability: Malicious Extensions and Gemini Panel

To protect against such threats, users should regularly monitor their installed extensions, remove those they don't use, and be vigilant about updates that introduce new features. Organizations should implement policies that limit the installation of extensions to only approved ones and keep Chrome installations up-to-date to receive critical security updates, according to the source.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
