Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Pixel Perfect Browser Extension Exploited for Stealth Script Injection and Security Header Stripping

The Chrome extension "QuickLens – Search Screen with Google Lens" has transitioned from a productivity tool to a platform capable of remote code execution, exploiting browser trust, security headers, and silent auto-updates. Initially, it functioned as a…

The Chrome extension "QuickLens – Search Screen with Google Lens" has transitioned from a productivity tool to a platform capable of remote code execution, exploiting browser trust, security headers, and silent auto-updates. Initially, it functioned as a Google Lens wrapper but evolved into a campaign capable of injecting scripts into any visited site.

Early versions of QuickLens utilized a background service worker for window and capture management, alongside a content script for UI overlays. Network calls were limited to Google domains, with no obfuscation or suspicious logic. The extension's permissions, which included activeTab, scripting, screen capture, and a content script for all pages, appeared standard for its functionality.

Ownership Change and Malicious 5.8 Release

QuickLens was listed for sale on ExtensionHub shortly after its launch, a common practice in extension-based supply chain attacks. On Feb 1, 2026, control shifted to "LLC Quick Lens," and a new privacy policy was introduced, signaling a possible throwaway entity. By Feb 17, 2026, version 5.8 was released, incorporating declarativeNetRequestWithHostAccess and webRequest permissions, a rules.json file, and a C2-aware background.js file, which were absent in the benign 5.7 version.

Google has removed the extension due to a "policy violation," but the changes indicate a clear attempt to bypass browser defenses and monetize user browsing sessions. The rules.json file uses Chrome's declarativeNetRequest API to modify HTTP responses, removing key security headers to allow inline script execution and other vulnerabilities.

The updated background script connects to api.extensionanalyticspro.top, registering a persistent UUID, fingerprinting the user's country, collecting browser/OS data, and polling for instructions. The server provides JavaScript strings stored in local storage, with webRequest handlers triggering on-demand refreshes. Execution occurs via a hidden 1×1 GIF element, allowing arbitrary script execution in the page context.

For defenders, this incident underlines the necessity of treating browser extensions as part of the enterprise supply chain, monitoring ownership changes, flagging new network permissions, and employing runtime behavior analysis to detect covert script injection.

Initially, it functioned as a Google Lens wrapper but evolved into a campaign capable of injecting scripts into any visited site.
Anna Fields · Thehackingpost

Type Value

Extension ID kdenlnncndfnhkognokgfpabgkgehodd

Extension Name QuickLens – Search Screen with Google Lens

C2 Domain api.extensionanalyticspro[.]top

Advertisement

Developer Email support@doodlebuggle[.]top

Privacy Policy kowqlak[.]lat

Malicious Version 5.8

SHA256 fa3d0c8c8e9f3dacaa9f34e42ad63dceeba16689e055b90e9a903fa274d35df0

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories