Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal
ID: 3ebcc6f8-f510-5079-9c26-52e8890796ea
STIX ID: report--3ebcc6f8-f510-5079-9c26-52e8890796ea
Feed Name: cybersecurityNews.com
Threat Score
A Featured Chrome extension named QuickLens (7,000 users) was sold to a throwaway owner and, in version 5.8 (released 2026-02-17), silently gained a C2, new permissions (declarativeNetRequestWithHostAccess and webRequest), and a rules.json that stripped CSP and other security headers; the extension then executes runtime-delivered JavaScript across pages using a 1×1 transparent GIF (pixel trick), allowing token theft, form scraping, and covert data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
