QuickLens Chrome extension steals crypto, shows ClickFix attack
2026-03-04T20:03:35Z•307b8df0d5cf7eecc0a3cc7e5dd911e64e1339f478f7274d12e2fb6435c1bac3
CVE-2025-0282RESURGEair-gap-bridgingapex-oneapt37chrome-extensionclickjackingcrypto-theftdata-breacheuropolgemini-exposuregoogle-api-keysivantijuniperjunoslaw-enforcementmalicious-extensionmanomanoransomwarerceremovable-drive-malwarerouter-takeoverseed-phrase-exposuretrend-micro
What happened
Multiple high-impact incidents and vulnerabilities reported: a malicious Chrome extension (“QuickLens”) was removed after being used to push malware and steal cryptocurrency via a ClickFix-style attack; South Korea’s National Tax Service accidentally published a seized wallet’s mnemonic seed, enabling theft of ~6.4B won (~$4.8M); CISA warns RESURGE implant can remain dormant on Ivanti Connect Secure devices (exploiting CVE-2025-0282); a critical Juniper PTX/Junos OS flaw allows unauthenticated remote code execution and full router takeover; Trend Micro patched two critical Apex One RCE flaws;A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 307b8df0d5cf7eecc0a3cc7e5dd911e64e1339f478f7274d12e2fb6435c1bac3
- Enrichment time
- 2026-03-04T20:03:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.