The420.In QuickLens Chrome Extension Compromised to Steal Crypto Credentials
Article Content
Browse articles
The QuickLens Chrome extension, which allowed users to perform Google Lens searches, was compromised on February 17, 2026, with the release of version 5.8 that introduced malware capable of stealing cryptocurrency credentials. Approximately 7,000 users were affected before the extension was removed from the Chrome Web Store. Researchers identified that the malicious update enabled remote code execution, posing significant risks to users' crypto assets.
Ask AI about this cluster
Answers cite the sources they use
Updated 196d ago How this analysis works
Timeline
2026-02-17
Version 5.8 of QuickLens released with malware
2026-02-28
QuickLens removed from Chrome Web Store
2026-03-02
The420.In article published on the incident
More articles in this cluster (8)
Following this threat?
Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…