Two Google Chrome extensions, QuickLens and ShotBird, were recently identified as malicious following a change in ownership. These extensions, which previously held legitimate reputations and “Featured” badges, were updated to inject arbitrary code, exfiltrate sensitive data, and deliver malware to users.
Affected Extensions
- QuickLens – Search Screen with Google Lens(7,000+ users): Reported as removed from the Chrome Web Store after being updated on February 17, 2026, with malicious scripts.
- ShotBird – Scrolling Screenshots, Tweet Images & Editor (800+ users): Originally launched in November 2024; it reportedly remained accessible shortly after the discovery.
Malicious Activities
The malicious updates introduced several high-risk behaviors:
- Security Header Stripping: The code was modified to remove security headers like
Content-Security-Policy (CSP) and X-Frame-Options from HTTP responses. This bypasses standard browser protections and allows injected scripts to make unauthorized requests to other domains.
- Arbitrary Code Execution: The extensions poll an external command-and-control (C2) server every five minutes to download and execute JavaScript.
- Data Theft & ClickFix Attacks: The compromised extensions were used to steal cryptocurrency wallet seed phrases and deliver “ClickFix” attacks, which trick users into downloading malicious executables via fake Google update alerts.
- User Fingerprinting: Malicious scripts collected data on the user’s country, browser, and operating system.
Recommended Actions
If you have these extensions installed:
- Remove immediately: Navigate to
chrome://extensions/ and uninstall the affected add-ons.
- Clear browser data: Clear all cookies and site data to remove persistent tracking mechanisms.
- Revoke credentials: Reset passwords and revoke session tokens for sensitive accounts, especially cryptocurrency wallets and banking.
- Run a security scan: Use reputable antivirus software to check for any malware that may have been downloaded via the extension.