Chrome Extension Hijacked to Deliver Malware, Steal Crypto Wallets
ID: e1f08a52-4605-5cc3-8dad-9790a31db508
STIX ID: report--e1f08a52-4605-5cc3-8dad-9790a31db508
Feed Name: TechRepublic Security
Threat Score
QuickLens, a previously trusted Chrome extension with ~7,000 users, was hijacked via an ownership change and silently updated to strip browser security headers, add C2 communications (api.extensionanalyticspro.top), and deliver malicious JavaScript and binaries that enable ClickFix social-engineering downloads, remote code execution, and theft of cryptocurrency wallet seeds and other credentials; Google removed and disabled the extension after disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
