Skip to content
QuickLens Chrome Extension Compromised to Steal Crypto Credentials

QuickLens Chrome Extension Compromised to Steal Crypto Credentials

First seen 2 Mar 2026, 06:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

The QuickLens Chrome extension, which allowed users to perform Google Lens searches, was compromised on February 17, 2026, with the release of version 5.8 that introduced malware capable of stealing cryptocurrency credentials. Approximately 7,000 users were affected before the extension was removed from the Chrome Web Store. Researchers identified that the malicious update enabled remote code execution, posing significant risks to users' crypto assets.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 196d ago How this analysis works

Timeline

2026-02-17
Version 5.8 of QuickLens released with malware
2026-02-28
QuickLens removed from Chrome Web Store
2026-03-02
The420.In article published on the incident

More articles in this cluster (8)

Following this threat?

Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed