Chrome Extensions Turn Malicious After Ownership Transfer: The Supply Chain Attack You Didn't See Coming
Two Chrome Featured extensions, QuickLens and ShotBird, turned malicious after ownership transfer. Attackers stripped security headers, injected C2 payloads via 1x1 pixel images, and deployed ClickFix-style attacks for full endpoint compromise. Extension supply chain attacks are accelerating.