QuickLens Chrome extension steals crypto, shows ClickFix attack

2026-03-04T20:22:45Zb588a0b4eb42334f814e76849ddac5af607b666ddffab5ce08a23fdaa02e98e7
CVE-2025-0282RESURGEair-gapped-networksapex-oneapt37chrome-extensionclickfix-attackcrypto-theftdata-leakgemini-exposuregoogle-api-keysivantijuniper-ptxjunos-os-evolvedmalwaremanomano-breachmnemonic-leakquicklensrceremote-code-executionremovable-mediaseed-phrase-exposuresupply-chainthird-party-patchingtrend-micro

What happened

A batch of BleepingComputer reports (late Feb 2026) highlights multiple high-impact incidents: a compromised Chrome extension called QuickLens was removed after being used to push malware and steal cryptocurrency via a ClickFix-style attack; South Korea's tax agency accidentally leaked a seized wallet’s mnemonic, enabling theft of ~6.4 billion won (~$4.8M); CISA warns of RESURGE implants persisting on Ivanti Connect Secure devices exploiting CVE-2025-0282; Juniper PTX routers have a critical Junos OS Evolved vulnerability enabling unauthenticated full takeover; Trend Micro patched critical RCE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b588a0b4eb42334f814e76849ddac5af607b666ddffab5ce08a23fdaa02e98e7
Enrichment time
2026-03-04T20:22:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · QuickLens Chrome extension steals crypto, shows ClickFix attack · Baitaphish