Malware-Tainted QuickLens Chrome Extension Steals Cryptocurrency Data
QuickLens, a screen color-picking and search extension once featured by the Google Chrome Web Store, had about 7,000 users. Browser extensions can read webpage content and login information, meaning a compromised software-update supply chain can directly threaten account credentials and cryptocurrency wallet assets.
Security researchers found that QuickLens version 5.8 had been injected with malicious JavaScript. The hackers also impersonated venture capitalists and used the ClickFix technique to trick victims into executing commands that stole credentials and cryptocurrency wallet data. Google has removed the extension from the Chrome Web Store and automatically disabled it for about 7,000 users.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →