QuickLens Chrome extension steals crypto, shows ClickFix attack
2026-03-04T20:22:45Z•b588a0b4eb42334f814e76849ddac5af607b666ddffab5ce08a23fdaa02e98e7
CVE-2025-0282RESURGEair-gapped-networksapex-oneapt37chrome-extensionclickfix-attackcrypto-theftdata-leakgemini-exposuregoogle-api-keysivantijuniper-ptxjunos-os-evolvedmalwaremanomano-breachmnemonic-leakquicklensrceremote-code-executionremovable-mediaseed-phrase-exposuresupply-chainthird-party-patchingtrend-micro
What happened
A batch of BleepingComputer reports (late Feb 2026) highlights multiple high-impact incidents: a compromised Chrome extension called QuickLens was removed after being used to push malware and steal cryptocurrency via a ClickFix-style attack; South Korea's tax agency accidentally leaked a seized wallet’s mnemonic, enabling theft of ~6.4 billion won (~$4.8M); CISA warns of RESURGE implants persisting on Ivanti Connect Secure devices exploiting CVE-2025-0282; Juniper PTX routers have a critical Junos OS Evolved vulnerability enabling unauthenticated full takeover; Trend Micro patched critical RCE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b588a0b4eb42334f814e76849ddac5af607b666ddffab5ce08a23fdaa02e98e7
- Enrichment time
- 2026-03-04T20:22:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.