Hijacked Chrome Extension Used to Steal Crypto Wallet Data
-

In a separate campaign, hackers compromised a Chrome extension called QuickLens to distribute malware targeting crypto users. According to Annex Security, the extension changed ownership on February 1, and a malicious update released weeks later embedded scripts designed to launch ClickFix attacks and steal sensitive information. The extension, which had around 7,000 users, has since been removed from the Chrome Web Store.
The malware reportedly searched for crypto wallet data and seed phrases while also scraping Gmail inboxes, YouTube accounts, login credentials, and payment information. Security experts note that ClickFix campaigns have increasingly targeted multiple industries, with warnings previously issued by Microsoft and research from Unit42 highlighting the method’s growing global reach.