logo

Pixel Perfect Browser Extension Exploited for Stealth Script Injection and Security Header Stripping

ID: 90de7e88-81e1-578e-b45e-7d47a31d0f8f

STIX ID: report--90de7e88-81e1-578e-b45e-7d47a31d0f8f

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A popular Chrome extension, QuickLens, was covertly sold and updated to a malicious v5.8 that added declarativeNetRequest and webRequest permissions, strips CSP and related security headers, and becomes a C2 client (api.extensionanalyticspro.top). The malicious code is delivered at runtime and executed in page context using a hidden 1×1 GIF onload injection technique, enabling arbitrary script execution, session/form scraping, and exfiltration across ~7,000 installs; the report includes extension ID, C2 domain, developer email, malicious version, and a SHA256 hash as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.