logo

QuickLens Chrome extension steals crypto, shows ClickFix attack

ID: 31d95e99-2128-5d3a-a181-d11789b775f6

STIX ID: report--31d95e99-2128-5d3a-a181-d11789b775f6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-28

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A malicious update to the QuickLens Chrome extension (v5.8) compromised thousands of users by removing security headers and executing remote JavaScript from a command-and-control server, delivering fake Google Update/ClickFix prompts that led to malware downloads and PowerShell-based second stages, and deploying agents to steal cryptocurrency wallets, login credentials, and account data; Google removed and disabled the extension and users are advised to remove it, scan systems, reset credentials, and move crypto funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.