The QuickLens – Search Screen with Google Lens Chrome extension was removed from the Chrome Web Store after a change in ownership led to a malicious update that turned the previously legitimate, Google-featured extension into a malware delivery and remote code execution platform affecting roughly 7,000 users. Researchers reported the extension was listed for sale on ExtensionHub shortly after its initial release, and ownership later transferred to an unverified entity using support@doodlebuggle.top under “LLC Quick Lens,” with related policy/identity infrastructure moved to low-reputation domains. A subsequent update (version 5.8) introduced a command-and-control (C2) channel and new high-risk permissions, enabling covert script injection and follow-on abuse.
Analysis of the malicious build found it embedded C2 communications to api.extensionanalyticspro[.]top, generated a persistent UUID, fingerprinted victims (including geolocation via Cloudflare trace), and polled for instructions on a recurring interval. The update also added a rules.json configuration and permissions (including declarativeNetRequestWithHostAccess and webRequest) used to strip browser security headers—including CSP, X-Frame-Options, and X-XSS-Protection—to make in-browser script execution easier. Reporting also tied the activity to ClickFix-style social engineering and crypto theft attempts, illustrating how “silent” extension updates and ownership transfers can rapidly weaponize trusted browser add-ons at scale.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
After the malicious behavior was identified, Google removed QuickLens from the Chrome Web Store and automatically disabled the extension for affected users. Security guidance advised users to remove the extension, scan for malware, reset passwords, and move cryptocurrency to new wallets if exposed.
As part of the campaign, QuickLens displayed fake Google Update alerts that lured users into a ClickFix-style infection chain. Windows users were prompted to run a signed malicious executable that led to PowerShell-based remote code execution, and reports indicated macOS users may also have been targeted with info-stealing malware.
Following the v5.8 release, the extension started polling its C2 for JavaScript, storing it locally, and executing it on visited pages. The injected code enabled victim fingerprinting, form and session data theft, credential harvesting, and scraping of services and cryptocurrency wallets.
On February 17, 2026, version 5.8 of the QuickLens Chrome extension was released to roughly 7,000 users. The update added high-risk permissions, introduced command-and-control communications, and removed key browser security protections from web traffic.
After QuickLens was listed for sale on an extension marketplace, ownership transferred to an unverified entity tied to supportdoodlebuggle.top. This ownership change set the stage for the later malicious update.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.