Mark RadarMARK RADAR
About
EN
Sign in
Event File CRYPTO Supply Chain Attacks

Malware-Tainted QuickLens Chrome Extension Steals Cryptocurrency Data

2 reports · First detected 2026-03-02 · Last active 2026-03-03

QuickLens, a screen color-picking and search extension once featured by the Google Chrome Web Store, had about 7,000 users. Browser extensions can read webpage content and login information, meaning a compromised software-update supply chain can directly threaten account credentials and cryptocurrency wallet assets.

Security researchers found that QuickLens version 5.8 had been injected with malicious JavaScript. The hackers also impersonated venture capitalists and used the ClickFix technique to trick victims into executing commands that stole credentials and cryptocurrency wallet data. Google has removed the extension from the Chrome Web Store and automatically disabled it for about 7,000 users.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)