The QuickLens Chrome Extension Supply Chain Attack

Updated 5 Oct 2026 · Incident date 17 Feb 2026 · browser extension

PackageQuickLens (kdenlnncndfnhkognokgfpabgkgehodd), ~7,000 users; related case ShotBird (gengfhhkjekmlejbhmmopegofnoifnjp)
Filebackground service worker

QuickLens, a Chrome extension with about 7,000 users, received a malicious update on 17 February 2026. This happened after a new owner bought the extension. The related extension ShotBird changed owner in the same month and later showed fake Chrome update prompts.

No hacked account was needed. The attacker bought the extension and used the normal update path to reach existing users.

What happened

A buyer took over a trusted extension and pushed a harmful update. According to The Hacker News and Cyberwarzone, the original developer listed QuickLens on ExtensionHub on 11 October 2025. A new owner, support@doodlebuggle.top, took control on 1 February 2026. The malicious update went out on 17 February 2026.

The update kept the original features and added new code. It:

ShotBird has a related story. It had about 800 users and the same original developer. Its ownership moved to another email address in February 2026. The reports say it showed a fake Chrome update prompt, led users to run a PowerShell command in a ClickFix-style page, downloaded googleupdate.exe on Windows, and captured data typed into form fields. Both extensions share command patterns, and the reports say the same actor is likely behind both.

Vigilance compares the version you trust with the new one. A new owner changes nothing in the store listing, but the new version gains new capability. Vigilance reports the file that gained it. See the scan block below.

Affected versions

The sources do not give version numbers for the malicious builds.

Indicators of compromise

The sources name no command-server domains, so this page lists none.

How to check

Open chrome://extensions and look for the two names. You can also search the Chrome profile folders for the IDs. On macOS:

ls ~/Library/Application\ Support/Google/Chrome/*/Extensions | grep -E "kdenlnncndfnhkognokgfpabgkgehodd|gengfhhkjekmlejbhmmopegofnoifnjp"

On Windows, run the same search under %LOCALAPPDATA%\Google\Chrome\User Data\*\Extensions. Also search for a file named googleupdate.exe outside the real Google Update folders.

What to do now

  1. Remove QuickLens and ShotBird from every browser profile.
  2. If anyone ran a PowerShell command from a fake Chrome update page, treat that machine as infected and reinstall it.
  3. Change passwords and tokens that were used in the browser while the extension was installed. Use a clean device.
  4. Audit the other extensions in your browsers. Remove ones you do not use.
  5. Install only extensions that you need, and watch for an ownership change before you trust an update.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old QuickLens-prev --new QuickLens-current
files scanned: 13 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   background.js
           It downloads from the internet and restarts itself after a reboot.

Frequently asked questions

How did the QuickLens extension turn malicious?

A new owner took control of QuickLens on 1 February 2026 after it was listed for sale. On 17 February 2026 the new owner pushed an update that added code to run remote JavaScript in pages.

Which Chrome extensions are linked to the QuickLens attack?

ShotBird (ID gengfhhkjekmlejbhmmopegofnoifnjp) is the related case. It changed owner in February 2026 and later showed fake Chrome update prompts.

Sources

  1. thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html
  2. cyberwarzone.com/2026/03/16/chrome-extensions-turned-malicious-after-ownership-transfer-pushing-code-injection-and-fake-updates/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free