#QuickLens
QuickLens Chrome extension steals crypto, shows ClickFix attack
QuickLens Chrome extension steals crypto, shows ClickFix attack
A Chrome extension named "QuickLens - Search Screen with Google Lens" has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of users.
www.bleepingcomputer.com
February 28, 2026 at 7:25 PM
A Chrome extension named "QuickLens - Search Screen with Google Lens" has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of users.
QuickLens Chrome extension steals crypto, shows ClickFix attack
A Chrome extension named "QuickLens - Search Screen with Google Lens" has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of users.
www.bleepingcomputer.com
February 28, 2026 at 7:19 PM
SQRF from Quicklens

Qieto2week Rich Special Offer - $2 off per box
Qieto2week Rich (6 Pack) | quicklens
Qieto2week Rich (6 Pack) QUICKLENS Australia offers contact lenses with cheap prices online. 10% Off your first order, Free Shipping on orders $99+, and great regular promotions! QUICKLENS
t.cfjump.com
March 13, 2025 at 12:20 PM
October Special from Quicklens

All colour contact lenses are on sale, up to $5 off per box.

No coupon code is required.
quicklens
Contact lenses for a Modern Vision Experience
t.cfjump.com
September 30, 2025 at 10:12 PM
Samsung data collection, QuickLens malware targeting users, South Korean tax agency crypto theft, Kimwolf botnet activity - a busy week in cybersecurity. Hospitals are particularly vulnerable to ransomware attacks. #Cybersecurity #ransomware #cryptocrime
March 2, 2026 at 11:09 AM
🚨 Crypto Alert: Sophisticated "ClickFix" attacks are escalating! Hackers impersonate VCs to trick users into compromising browser extensions like QuickLens, aiming to steal wallet data & seed phrases. ~7k users affected. Verify VC outreach & avoid running external commands! #CryptoSecurity #Phishing
Cryptovka
CryptoMarket and Blockchain News
cryptovka.com
March 3, 2026 at 5:24 AM
Notícia da BleepingComputer

"QuickLens Chrome extension steals crypto, shows ClickFix attack" #bolhasec
QuickLens Chrome extension steals crypto, shows ClickFix attack
A Chrome extension named "QuickLens - Search Screen with Google Lens" has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of ...
www.bleepingcomputer.com
March 20, 2026 at 2:30 PM
Notícia da BleepingComputer

"QuickLens Chrome extension steals crypto, shows ClickFix attack" #bolhasec
QuickLens Chrome extension steals crypto, shows ClickFix attack
A Chrome extension named "QuickLens - Search Screen with Google Lens" has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of ...
www.bleepingcomputer.com
March 5, 2026 at 5:30 PM
Extensão do Chrome virou ferramenta de espionagem com milhares de vítimas
Duas extensões do Google Chrome com selo de qualidade da própria loja do navegador foram transferidas para novos proprietários e, em seguida, atualizadas com código malicioso. As extensões QuickLens e ShotBird somavam cerca de 7.800 usuários e todos receberam as atualizações comprometidas sem qualquer aviso. O QuickLens passou a desativar barreiras de segurança do navegador, coletar informações do dispositivo e buscar instruções em servidores externos a cada cinco minutos. O ShotBird exibia um aviso falso de atualização do Chrome para induzir o usuário a instalar um programa que capturava senhas, dados de cartão e histórico de navegação. Pesquisadores da Annex Security e do monxresearch-sec avaliaram que o mesmo grupo está por trás dos dois ataques. Usuários que tinham as extensões instaladas devem removê-las imediatamente.
www.tecmundo.com.br
March 9, 2026 at 8:46 PM
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft

Two Google Chrome extensions have turned malicious after what appears to be a case of ownership transfer, offering attackers a way to push malware to downstream customers, inject arbitrary code, and…
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
Two Google Chrome extensions have turned malicious after what appears to be a case of ownership transfer, offering attackers a way to push malware to downstream customers, inject arbitrary code, and harvest sensitive data. The extensions in question, both originally associated with a developer named "akshayanuonline@gmail.com" (BuildMelon), are listed below - QuickLens - Search Screen with Google Lens (ID: kdenlnncndfnhkognokgfpabgkgehodd) - 7,000 users…
nexttech-news.com
March 17, 2026 at 1:47 AM
These new abilities power a new Kindlings release, which adds Hearth-bases:
- macwire-like DI
- mocking
- lenses
- cats-tagless derivation
- Tapir module for OpenAPI rendering with Jsoniter that would not pull-in Circe!

and more!

github.com/kubuszok/kin...
Release 0.3.0 - Compile-time DI, mocking, optics & OpenAPI-jsoniter modules, cats-tagless derivation, built on Hearth 0.4.0 · kubuszok/kindlings
Four brand-new Hearth-based modules — compile-time dependency injection (macwire-style), mocking (ScalaMock-style), optics (quicklens-style), and a Circe-free OpenAPI jsoniter serializer — plus a n...
github.com
June 26, 2026 at 6:19 PM
Hearth 0.4.0 once again is pushing the limits of what you can do with macros (without going insane):
- reworked method callers that could let you build every call
- expression destructuring enabling quicklens-like patterns
- creating anonymous instance of an arbitrary type
June 26, 2026 at 6:19 PM
📰 Ekstensi Chrome QuickLens Diretas, Curi Kripto dan Jalankan Serangan ClickFix

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/03/05/ekstensi-chrome-quicklens-malware-kriptostealer/

#eks
te#ekstensiBrowserl#googleChromea#keamananSibert#kriptoa#malware
March 5, 2026 at 2:43 PM
QuickLens─Search Screen with Google Lens

曾獲 Google 推薦卻暗藏惡意程式,QuickLens 擴充功能淪為加密貨幣竊取工具 infosecu.technews.tw/2026/03/02/g...
曾獲 Google 推薦卻暗藏惡意程式,QuickLens 擴充功能淪為加密貨幣竊取工具
2 月 17 日,一款名為「QuickLens─Search Screen with Google Lens」的 Chrome 擴充程式被發現已被惡意攻擊者入侵,並在其 5.8 版本中加入了竊取使用者憑證和加密貨幣的功能。這起事件引起關注,因為該擴充程式曾是 Google 推薦的工具,並在短時間內吸...
infosecu.technews.tw
March 2, 2026 at 9:02 AM
QuickLens Chrome extension steals crypto, shows ClickFix attack
QuickLens Chrome extension steals crypto, shows ClickFix attack
www.bleepingcomputer.com
March 1, 2026 at 3:21 AM
Chrome extensions turned malicious after ownership transfer, pushing code injection and fake updates
Chrome extensions turned malicious after ownership transfer, pushing code injection and fake updates - Cyberwarzone
Two Chrome extensions, QuickLens and ShotBird, turned malicious after ownership changes, enabling attackers to inject arbitrary code, strip security headers, display fake Chrome update prompts, and steal sensitive data from downstream users.
cyberwarzone.com
March 16, 2026 at 5:50 AM
Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal
Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal
A browser extension that once earned a Featured badge from Google quietly turned into a remote code execution tool after its ownership changed hands, exposing thousands of users to covert script injection and full browser security header stripping. The campaign, centered on a legitimate-looking Google Lens wrapper called QuickLens, highlights how even a well-reviewed, functional extension can be weaponized overnight through a single silent update.​ QuickLens was a practical tool that let users search images using Google Lens directly from the browser. It offered screen capture, area selection, YouTube frame search, and an Amazon product lookup. The extension grew to 7,000 active users and received a Featured badge from Google. It was first published to the Chrome Web Store on October 9th, 2025, and just two days later, on October 11th, it was listed for sale on ExtensionHub — a marketplace where developers sell their extensions, including their existing user base.​ Annex analysts identified this threat at multiple stages, starting with the sale listing in October 2025. On February 1st, 2026, the extension’s ownership transferred to an unverified entity operating under the domain supportdoodlebuggle.top, registered as LLC Quick Lens — a throwaway identity with no verifiable presence online. The privacy policy was relocated to kowqlak.lat. On February 17th, version 5.8 was released, and with it, a fully operational command-and-control (C2) platform was quietly pushed to all 7,000 users.​ QuickLens 5.8 became a remote code execution platform (Source – Annex) The update introduced three core changes: a new C2 server at api.extensionanalyticspro.top embedded in the background service worker, two new permissions — declarativeNetRequestWithHostAccess and webRequest — and a brand-new rules.json file. For most users, this came through as a standard permission update prompt — the kind most people accept without review.​ The rules.json file caused the most immediate harm. It instructed the extension to remove all meaningful browser security headers from every HTTP response, including Content-Security-Policy (CSP), X-Frame-Options, and X-XSS-Protection. This effectively stripped protection from every page visited, leaving users exposed to clickjacking, cross-site scripting, and unrestricted cross-domain requests.​ The Pixel Injection Mechanism The execution technique at the core of this attack is built around a deceptively simple trick. The C2 server delivers JavaScript code to the extension in the form of an array of strings, which is saved in the browser’s local storage under the label  cached-agents-data . On every page visited, the extension reads this stored payload and executes it through a 1×1 transparent GIF image — the technique researchers refer to as the pixel trick.​ The extension creates a hidden image element inside the web page, with its source set to a 1×1 transparent GIF encoded as a base64 data URI. This image loads instantly without making any outbound network request. The JavaScript payload from the C2 server is then attached as an inline  onload  attribute on that image element. The moment the browser processes the image, the script executes in the full context of the current page, giving the attacker direct access to everything on screen. This technique works precisely because Content-Security-Policy would normally block inline event handlers on any well-configured site. Since version 5.8 stripped CSP headers globally, the payload runs freely across every page visited. Malicious Update (Source – Annex) The injected code can read session tokens, capture form inputs, scrape page content, and send stolen data to external servers — all while the extension continues functioning normally as a Google Lens tool, leaving users with no reason to suspect anything is wrong.​ What makes this attack especially difficult to detect is that the malicious payload never appears inside the extension’s source files. Static code analysis reveals nothing more than a function that creates image elements. The JavaScript arrives from the C2 server only at runtime. Even the internal naming —  safelyProcessElement ,  cached-agents-data ,  extensionanalyticspro  — is designed to blend in as routine browser activity.​ Organizations should enforce strict browser extension allowlisting and actively monitor for unexpected permission changes, particularly new declarativeNetRequest and webRequest permissions. Users should regularly audit installed extensions and treat unsolicited permission update prompts as a warning sign. Extensions that change ownership should be reviewed carefully before continued use. IoCs Type Value Extension ID kdenlnncndfnhkognokgfpabgkgehodd Extension Name QuickLens – Search Screen with Google Lens Malicious Version 5.8 C2 Domain api.extensionanalyticspro.top Developer Email support@doodlebuggle.top Privacy Policy Domain kowqlak.lat SHA-256 fa3d0c8c8e9f3dacaa9f34e42ad63dceeba16689e055b90e9a903fa274d35df0 Removal Date 2026-02-17 Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal appeared first on Cyber Security News .
cybersecuritynews.com
March 2, 2026 at 8:11 AM
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft

Two Google Chrome extensions have turned malicious after what appears to be a case of ownership transfer, offering attackers a way to push malware to downstream customers, inject arbitrary code, and…
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
Two Google Chrome extensions have turned malicious after what appears to be a case of ownership transfer, offering attackers a way to push malware to downstream customers, inject arbitrary code, and harvest sensitive data. The extensions in question, both originally associated with a developer named "akshayanuonline@gmail.com" (BuildMelon), are listed below - QuickLens - Search Screen with Google Lens (ID: kdenlnncndfnhkognokgfpabgkgehodd) - 7,000 users…
nexttech-news.com
March 17, 2026 at 1:47 AM
QuickLens Chrome extension steals crypto, shows ClickFix attack

https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/

#CyberSecurity #InfoSec
March 1, 2026 at 7:40 AM
🚨 QuickLens Chrome extension steals crypto, shows ClickFix attack

https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/

#CyberSecurity #InfoSec
February 28, 2026 at 7:28 PM
March 9, 2026 at 8:45 PM
March 2, 2026 at 3:00 PM
Malicious QuickLens Chrome Extension Used To Steal Crypto And Passwords

A popular Chrome extension called QuickLens Search Screen with Google Lens has been removed from the Chrome Web Store after it was hijacked and turned into a malware delivery tool targeting thousands of users.
Malicious QuickLens Chrome Extension Used To Steal Crypto And Passwords
A popular Chrome extension called QuickLens Search Screen with Google Lens has been removed from the Chrome Web Store after it was hijacked and turned into a malware delivery tool targeting thousands of users.
www.abijita.com
March 1, 2026 at 2:12 AM