Chrome Extension Supply Chain Attack — QuickLens/ShotBird Ownership Transfer Hijack (CVE-less) — Threadlinqs Intelligence
As of 2026-05-30, Chrome Extension Supply Chain Attack — QuickLens/ShotBird Ownership Transfer Hijack (CVE-less) is a high-severity supply chain threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0203 · Severity: HIGH · CVSS: 8.1 · Status: MONITORING · Category: SUPPLY_CHAIN
Attribution: Russia · FINANCIAL
Threat actors acquired legitimate Chrome extensions QuickLens (~7,000 users) and ShotBird (~800 users) through marketplace ownership transfers, weaponizing update channels to deploy C2-driven malware,
A coordinated supply chain campaign compromised two previously trusted Chrome extensions — QuickLens (ID: kdenlnncndfnhkognokgfpabgkgehodd) and ShotBird (ID: gengfhhkjekmlejbhmmopegofnoifnjp) — through developer account ownership transfers facilitated by the ExtensionHub marketplace.
QuickLens, originally a Google Lens utility published by developer BuildMelon (akshayanuonline@gmail.com), was listed for sale on ExtensionHub on October 11, 2025. On February 1, 2026, ownership transferred to support@doodlebuggle.top under the entity 'LLC Quick Lens'. On February 17, 2026, malicious version 5.8 was pushed to approximately 7,000 users. The update requested expanded permissions (declarativeNetRequestWithHostAccess, webRequest) and introduced a rules.json that stripped Content-Security-Policy, X-Frame-Options, and X-XSS-Protection headers from all HTTP responses.
The extension communicated with the C2 server api.extensionanalyticspro[.]top every 5 minutes, generating a persistent UUID for bot identification, fingerprinting the victim's country via Cloudflare's trace endpoint, and detecting browser/OS. Malicious JavaScript payloads were delivered through the C2 and executed on every page load using a covert 1x1 GIF pixel onload trick — a hidden img element whose onload handler executed attacker-supplied scripts.
The cryptocurrency theft module detected the presence of MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Solflare, Backpack, Brave Wallet, Exodus, Binance Chain Wallet, WalletConnect, and Argon crypto wallets. When found, it targeted seed phrases, private keys, and transaction histories for exfiltration. Additional data exfiltration targeted Gmail inbox contents, Facebook Business Manager advertising accounts, YouTube channel data, and general login credentials and payment information from web forms.
ShotBird, a screenshot and tweet image editor (~800 users, ID: gengfhhkjekmlejbhmmopegofnoifnjp), originally published November 2024 by the same developer (Akshay Anu S), received Chrome's Featured badge in January 2025. Ownership transferred to loraprice198865@gmail.com between December 2025 and February 2026. The malicious version communicated with api.getextensionanalytics[.]top using an identical callback-driven C2 architecture with /setup, /callback, /finish, and /uninstall endpoint families.
ShotBird's capabilities included keystroke capture on input, textarea, and select HTML elements targeting sensitive keywords (credentials, financial data, identity fields), Chrome stored data theft (passwords, browsing history, extension information), and injection of fake Chrome update overlays. The fake update templates were delivered from ggl[.]lat and used a ClickFix-style social engineering technique that instructed users to open the Windows Run dialog, execute cmd.exe, and paste a PowerShell command.
The ClickFix chain downloaded googleupdate.exe (SHA256: E8D2ED43386B322DA02C1CFCAEFEBD88D6B470D6CD11F02C20712CF1E8FD8413), a dropper signed with a fake certificate from 'Hubei Da'e Zhidao Food Technology Co., Ltd.' that bundled a legitimate ChromeSetup.exe with a malicious psfx.msi stager. The MSI executed encoded PowerShell that decoded to 'irm orangewater00.com|iex', fetching and executing a second-stage payload. Post-exploitation behavior captured via PowerShell Script Block Logging (Event ID 4104) on March 5, 2026 showed ETW suppression, Windows Credential Manager enumeration, and Chromium browser data targeting (Login Data, Web Data databases).
Code analysis revealed debug artifacts including console.log statements, debugLog wrapper functions, inline Russian-language comments ('Запускаем initApp после загрузки DOM'), and @ts-nocheck directives — indicators of low operational security and possible 'vibe-coded' development. The shared C2 architecture between both extensions confirms a single threat actor or coordinated group operating this campaign.
Possible macOS targeting with the AMOS infostealer variant was also noted
Weaknesses (CWE)
CWE-494, CWE-829, CWE-506
Target sectors: cryptocurrency, financial, technology, advertising, media, general-consumer
Target regions: Global, North America, Europe, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1195, T1176, T1059, T1204, T1185, T1056, T1539, T1555, T1056, T1027