logo

Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft

ID: 028c3765-35e5-5555-9c5f-a8e2acef83df

STIX ID: report--028c3765-35e5-5555-9c5f-a8e2acef83df

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-03-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Two Chrome extensions (QuickLens and ShotBird) were weaponized after ownership transfers to push remote JavaScript from a C2, bypass CSP and security headers, and execute runtime payloads that enable in-browser data harvesting and, in the case of ShotBird, a fake-update chain that leads to host-level execution (downloaded binary and credential capture); the report also highlights multiple other malicious/abusive Chrome extensions and large-scale redirect/hijack campaigns and advises immediate removal and auditing of browser extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.