The QuickLens Chrome Extension Supply Chain Attack
Updated 5 Oct 2026 · Incident date 17 Feb 2026 · browser extension
QuickLens (kdenlnncndfnhkognokgfpabgkgehodd), ~7,000 users; related case ShotBird (gengfhhkjekmlejbhmmopegofnoifnjp)background service workerQuickLens, a Chrome extension with about 7,000 users, received a malicious update on 17 February 2026. This happened after a new owner bought the extension. The related extension ShotBird changed owner in the same month and later showed fake Chrome update prompts.
No hacked account was needed. The attacker bought the extension and used the normal update path to reach existing users.
What happened
A buyer took over a trusted extension and pushed a harmful update. According to The Hacker News and Cyberwarzone, the original developer listed QuickLens on ExtensionHub on 11 October 2025. A new owner, support@doodlebuggle.top, took control on 1 February 2026. The malicious update went out on 17 February 2026.
The update kept the original features and added new code. It:
- stripped security headers such as
X-Frame-Optionsfrom HTTP responses, - fingerprinted the victim's country, browser and operating system,
- polled a remote server every five minutes for JavaScript to run,
- ran that code through a hidden 1x1 image element with an onload handler, and
- kept payloads in local storage so they never appeared in the source files.
ShotBird has a related story. It had about 800 users and the same original developer. Its ownership moved to another email address in February 2026. The reports say it showed a fake Chrome update prompt, led users to run a PowerShell command in a ClickFix-style page, downloaded googleupdate.exe on Windows, and captured data typed into form fields. Both extensions share command patterns, and the reports say the same actor is likely behind both.
Vigilance compares the version you trust with the new one. A new owner changes nothing in the store listing, but the new version gains new capability. Vigilance reports the file that gained it. See the scan block below.
Affected versions
- QuickLens - Search Screen with Google Lens, ID
kdenlnncndfnhkognokgfpabgkgehodd. Update of 17 February 2026. About 7,000 users. Removed from the Chrome Web Store. - ShotBird - Scrolling Screenshots, Tweet Images & Editor, ID
gengfhhkjekmlejbhmmopegofnoifnjp. About 800 users. The Hacker News reported it still listed when it published.
The sources do not give version numbers for the malicious builds.
Indicators of compromise
- Extension IDs:
kdenlnncndfnhkognokgfpabgkgehoddandgengfhhkjekmlejbhmmopegofnoifnjp. - Owner addresses named in the reports:
support@doodlebuggle.top(QuickLens) andloraprice198865@gmail.com(ShotBird). - File on Windows machines:
googleupdate.exe, downloaded after a fake Chrome update prompt. - Behavior: a request to an outside server every five minutes from the extension, and a hidden 1x1 image element in pages.
The sources name no command-server domains, so this page lists none.
How to check
Open chrome://extensions and look for the two names. You can also search the Chrome profile folders for the IDs. On macOS:
ls ~/Library/Application\ Support/Google/Chrome/*/Extensions | grep -E "kdenlnncndfnhkognokgfpabgkgehodd|gengfhhkjekmlejbhmmopegofnoifnjp"
On Windows, run the same search under %LOCALAPPDATA%\Google\Chrome\User Data\*\Extensions. Also search for a file named googleupdate.exe outside the real Google Update folders.
What to do now
- Remove QuickLens and ShotBird from every browser profile.
- If anyone ran a PowerShell command from a fake Chrome update page, treat that machine as infected and reinstall it.
- Change passwords and tokens that were used in the browser while the extension was installed. Use a clean device.
- Audit the other extensions in your browsers. Remove ones you do not use.
- Install only extensions that you need, and watch for an ownership change before you trust an update.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 13 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE background.js It downloads from the internet and restarts itself after a reboot.
Frequently asked questions
How did the QuickLens extension turn malicious?
A new owner took control of QuickLens on 1 February 2026 after it was listed for sale. On 17 February 2026 the new owner pushed an update that added code to run remote JavaScript in pages.
Which Chrome extensions are linked to the QuickLens attack?
ShotBird (ID gengfhhkjekmlejbhmmopegofnoifnjp) is the related case. It changed owner in February 2026 and later showed fake Chrome update prompts.
Sources
More supply chain attacks
- Offside Wallet Theft Factory (Firefox add-ons converted from sports-score tools) 9 Mar 2026
- Trust Wallet browser extension v2.68 compromise 24 Dec 2025
- RedDirection campaign (Color Picker Geco and 17 others) 27 Jun 2025
- Cyberhaven Chrome extension compromise 25 Dec 2024
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.