# Chrome Extension Supply Chain Attack — QuickLens/ShotBird Ownership Transfer Hijack (CVE-less)

> Threat actors acquired legitimate Chrome extensions QuickLens (~7,000 users) and ShotBird (~800 users) through marketplace ownership transfers, weaponizing update channels to deploy C2-driven malware, cryptocurrency wallet theft, ClickFix-style PowerShell execution chains, and form-data capture affecting approximately 7,800 users.

- **Published:** 2026-03-10T02:10:27Z
- **Last reviewed:** 2026-03-10T02:10:27Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0203
- **ID:** TL-2026-0203
- **Severity:** HIGH (CVSS 8.1)
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A coordinated supply chain campaign compromised two previously trusted Chrome extensions — QuickLens (ID: kdenlnncndfnhkognokgfpabgkgehodd) and ShotBird (ID: gengfhhkjekmlejbhmmopegofnoifnjp) — through developer account ownership transfers facilitated by the ExtensionHub marketplace.

QuickLens, originally a Google Lens utility published by developer BuildMelon (akshayanuonline@gmail.com), was listed for sale on ExtensionHub on October 11, 2025. On February 1, 2026, ownership transferred to support@doodlebuggle.top under the entity 'LLC Quick Lens'. On February 17, 2026, malicious version 5.8 was pushed to approximately 7,000 users. The update requested expanded permissions (declarativeNetRequestWithHostAccess, webRequest) and introduced a rules.json that stripped Content-Security-Policy, X-Frame-Options, and X-XSS-Protection headers from all HTTP responses.

The extension communicated with the C2 server api.extensionanalyticspro[.]top every 5 minutes, generating a persistent UUID for bot identification, fingerprinting the victim's country via Cloudflare's trace endpoint, and detecting browser/OS. Malicious JavaScript payloads were delivered through the C2 and executed on every page load using a covert 1x1 GIF pixel onload trick — a hidden img element whose onload handler executed attacker-supplied scripts.

The cryptocurrency theft module detected the presence of MetaMask, Phantom, Coinbase Wallet, Trust Wallet, Solflare, Backpack, Brave Wallet, Exodus, Binance Chain Wallet, WalletConnect, and Argon crypto wallets. When found, it targeted seed phrases, private keys, and transaction histories for exfiltration. Additional data exfiltration targeted Gmail inbox contents, Facebook Business Manager advertising accounts, YouTube channel data, and general login credentials and payment information from web forms.

ShotBird, a screenshot and tweet image editor (~800 users, ID: gengfhhkjekmlejbhmmopegofnoifnjp), originally published November 2024 by the same developer (Akshay Anu S), received Chrome's Featured badge in January 2025. Ownership transferred to loraprice198865@gmail.com between December 2025 and February 2026. The malicious version communicated with api.getextensionanalytics[.]top using an identical callback-driven C2 architecture with /setup, /callback, /finish, and /uninstall endpoint families.

ShotBird's capabilities included keystroke capture on input, textarea, and select HTML elements targeting sensitive keywords (credentials, financial data, identity fields), Chrome stored data theft (passwords, browsing history, extension information), and injection of fake Chrome update overlays. The fake update templates were delivered from ggl[.]lat and used a ClickFix-style social engineering technique that instructed users to open the Windows Run dialog, execute cmd.exe, and paste a PowerShell command.

The ClickFix chain downloaded googleupdate.exe (SHA256: E8D2ED43386B322DA02C1CFCAEFEBD88D6B470D6CD11F02C20712CF1E8FD8413), a dropper signed with a fake certificate from 'Hubei Da'e Zhidao Food Technology Co., Ltd.' that bundled a legitimate ChromeSetup.exe with a malicious psfx.msi stager. The MSI executed encoded PowerShell that decoded to 'irm orangewater00.com|iex', fetching and executing a second-stage payload. Post-exploitation behavior captured via PowerShell Script Block Logging (Event ID 4104) on March 5, 2026 showed ETW suppression, Windows Credential Manager enumeration, and Chromium browser data targeting (Login Data, Web Data databases).

Code analysis revealed debug artifacts including console.log statements, debugLog wrapper functions, inline Russian-language comments ('Запускаем initApp после загрузки DOM'), and @ts-nocheck directives — indicators of low operational security and possible 'vibe-coded' development. The shared C2 architecture between both extensions confirms a single threat actor or coordinated group operating this campaign.

Possible macOS targeting with the AMOS infostealer variant was also noted. Related malicious extensions in the same campaign ecosystem include Token Chromophore (fake imToken, ID: bbhaganppipihlhjgaaeeeefbaoihcgi) targeting 12/24-word seed phrases, and Chrome MCP Server (ID: fpeabamapgecnidibdmjoepaiehokgda) functioning as a RAT disguised as an AI automation tool.

---

**Revalidated on 2026-03-12**

Post-publication intelligence (March 9-12, 2026) confirms all original findings. Three additional details warrant inclusion: (1) Google actively auto-disabled QuickLens in affected browsers beyond just removing the Chrome Web Store listing, though PCRisk reports some installations may persist. (2) The MonxResearch ShotBird analysis reveals the second-stage payload is more sophisticated than initially assessed — PowerShell Script Block Logging captured a full browser-to-endpoint compromise chain including ETW (Event Tracing for Windows) suppression, Credential Manager enumeration, Chromium data targeting (saved passwords, cookies, autofill), and exfiltration upload logic, classifying this as a complete credential-theft platform rather than just extension-level data capture. (3) CoinTelegraph reporting links this campaign to a broader ClickFix operation where threat actors also impersonate venture capitalists to target cryptocurrency users, suggesting the QuickLens/ShotBird compromise may be one vector within a larger financially-motivated operation. No Google policy changes regarding extension ownership transfers have been announced despite this incident.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1176 Software Extensions
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1185 Browser Session Hijacking
- T1056 Input Capture
- T1539 Steal Web Session Cookie
- T1555 Credentials from Password Stores
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1553 Subvert Trust Controls
- T1140 Deobfuscate/Decode Files or Information
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1005 Data from Local System
- T1584 Compromise Infrastructure
- T1657 Financial Theft

## Sources

- [Chrome Extension Turns Malicious After Ownership Transfer — The Hacker News](https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html)
- [ShotBird Extension Malware Report — MonxResearch](https://monxresearch-sec.github.io/shotbird-extension-malware-report/)
- [QuickLens Chrome Extension Steals Crypto, Shows ClickFix Attack — BleepingComputer](https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/)
- [QuickLens Chrome Extension Supply Chain Attack Analysis — Rescana](https://www.rescana.com/post/quicklens-chrome-extension-supply-chain-attack-cryptocurrency-theft-and-clickfix-malware-campaign-a)
- [Chrome Extension Hijacked to Push ClickFix Malware — eSecurity Planet](https://www.esecurityplanet.com/threats/chrome-extension-hijacked-to-push-clickfix-malware/)
- [Chrome Extension Hijacked to Deliver Malware, Steal Crypto Wallets — TechRepublic](https://www.techrepublic.com/article/news-compromised-chrome-extension-malware-crypto-theft/)
- [Malicious Chrome Extension QuickLens Removed After Stealing Crypto — SC World](https://www.scworld.com/brief/malicious-chrome-extension-quicklens-removed-after-stealing-crypto-and-spreading-malware)
- [Crypto Hackers Impersonate VCs, Hijack Browser Extensions in ClickFix Scam — DeFi Planet](https://defi-planet.com/2026/03/crypto-hackers-impersonate-vcs-hijack-browser-extensions-in-evolving-clickfix-scam/)
- [The Chrome Extension Backdoor: Productivity Tools as Enterprise Attack Vectors — Security Boulevard](https://securityboulevard.com/2026/03/the-chrome-extension-backdoor-how-productivity-tools-became-enterprise-attack-vectors/)
- [The Hidden Cybersecurity Risk in Browser Extensions — Barracuda Networks](https://blog.barracuda.com/2026/02/25/hidden-cybersecurity-risk-browser-extensions)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0203
