QuickLens Chrome extension steals crypto, shows ClickFix attack

2026-03-04T20:03:35Z307b8df0d5cf7eecc0a3cc7e5dd911e64e1339f478f7274d12e2fb6435c1bac3
CVE-2025-0282RESURGEair-gap-bridgingapex-oneapt37chrome-extensionclickjackingcrypto-theftdata-breacheuropolgemini-exposuregoogle-api-keysivantijuniperjunoslaw-enforcementmalicious-extensionmanomanoransomwarerceremovable-drive-malwarerouter-takeoverseed-phrase-exposuretrend-micro

What happened

Multiple high-impact incidents and vulnerabilities reported: a malicious Chrome extension (“QuickLens”) was removed after being used to push malware and steal cryptocurrency via a ClickFix-style attack; South Korea’s National Tax Service accidentally published a seized wallet’s mnemonic seed, enabling theft of ~6.4B won (~$4.8M); CISA warns RESURGE implant can remain dormant on Ivanti Connect Secure devices (exploiting CVE-2025-0282); a critical Juniper PTX/Junos OS flaw allows unauthenticated remote code execution and full router takeover; Trend Micro patched two critical Apex One RCE flaws;A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
307b8df0d5cf7eecc0a3cc7e5dd911e64e1339f478f7274d12e2fb6435c1bac3
Enrichment time
2026-03-04T20:03:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · QuickLens Chrome extension steals crypto, shows ClickFix attack · Baitaphish