logo

Chrome Extension Hijacked to Deliver Malware, Steal Crypto Wallets

ID: e1f08a52-4605-5cc3-8dad-9790a31db508

STIX ID: report--e1f08a52-4605-5cc3-8dad-9790a31db508

Feed Name: TechRepublic Security

Threat Score
78/100

Date Published: 2026-03-03

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

QuickLens, a previously trusted Chrome extension with ~7,000 users, was hijacked via an ownership change and silently updated to strip browser security headers, add C2 communications (api.extensionanalyticspro.top), and deliver malicious JavaScript and binaries that enable ClickFix social-engineering downloads, remote code execution, and theft of cryptocurrency wallet seeds and other credentials; Google removed and disabled the extension after disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.