Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
Two Google Chrome extensions (QuickLens and Search Screen) turned malicious following an ownership transfer, allowing attackers to inject arbitrary code and steal sensitive data from users. The extensions were originally developed by a user associated with the email 'akshayanuonline@gmail.com' (BuildMelon) before being compromised. This incident represents a supply chain attack vector through compromised browser extensions targeting downstream users.
Summary
Two Google Chrome extensions (QuickLens and Search Screen) turned malicious following an ownership transfer, allowing attackers to inject arbitrary code and steal sensitive data from users. The extensions were originally developed by a user associated with the email 'akshayanuonline@gmail.com' (BuildMelon) before being compromised. This incident represents a supply chain attack vector through compromised browser extensions targeting downstream users.
Indicators of Compromise
- email — akshayanuonline@gmail.com
- malware — QuickLens - Search Screen Chrome Extension