The420.In
QuickLens Chrome Extension Compromised to Steal Crypto Credentials
First seen 2 Mar 2026, 06:09 UTC
•



+3
•81% similarity
•29.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The QuickLens Chrome extension, which allowed users to perform Google Lens searches, was compromised on February 17, 2026, with the release of version 5.8 that introduced malware capable of stealing cryptocurrency credentials. Approximately 7,000 users were affected before the extension was removed from the Chrome Web Store. Researchers identified that the malicious update enabled remote code execution, posing significant risks to users' crypto assets.
ThreatCluster AI
How this analysis works
Timeline
2026-02-17
Version 5.8 of QuickLens released with malware
2026-02-28
QuickLens removed from Chrome Web Store
2026-03-02
The420.In article published on the incident