Skip to main content
AVOID.NET

QuickLens Chrome Extension Supply Chain Attack

avoid.net/quicklens-chrome-extension-supply-chain-attack2/100·85% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

QuickLens ("Search Screen with Google Lens"), a Chrome extension with roughly 7,000 users, was allegedly acquired via an ownership transfer on February 1, 2026 and subsequently weaponized in a malicious update (version 5.8) released February 17, 2026. Security researchers documented crypto-wallet-draining code, ClickFix-style social-engineering malware delivery, and theft of Gmail, Facebook Business Manager, and YouTube data before Google removed the extension from the Chrome Web Store. A later report (August 2026) ties QuickLens to a broader 19-extension campaign of purchased-and-weaponized browser add-ons.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about QuickLens Chrome Extension Supply Chain Attack?

Timeline(5 events)

1 February 2026

Ownership of the QuickLens Chrome extension allegedly transferred to an account using the email support@doodlebuggle.top under the name "LLC Quick Lens", after being listed for sale on the ExtensionHub marketplace.

BleepingComputer

17 February 2026

Version 5.8 of QuickLens was released, allegedly containing malicious scripts enabling ClickFix-style malware delivery, wallet-draining code, and header-stripping functionality.

BleepingComputer

February 2026

BleepingComputer published its report on the QuickLens compromise, describing crypto wallet targeting, ClickFix attacks, and data theft from Gmail, Facebook, and YouTube.

BleepingComputer

March 2026

Forbes, The Hacker News, TechRepublic, SC Media, and other outlets published follow-up coverage of the QuickLens compromise, and the extension was removed from the Chrome Web Store.

Forbes

27 August 2026

Security research firm Socket published findings on a broader campaign ("Superior") of 19 Chrome and Edge extensions, including QuickLens, purchased from original developers and weaponized with wallet-draining code.

The Hacker News
Provenance & Audit Trail
9 Wayback Archives

9 of 10 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/19/2026, 12:09:35 PM

last updated: 9/19/2026, 2:10:18 PM

avoid.net — verified advice for a post-truth world