Security · 1h ago
Fake Google Notes Extension Steals Crypto by Swapping Wallet Addresses
McAfee Labs uncovered a campaign called Silent Swap that uses fake Google Notes browser extensions to replace cryptocurrency wallet addresses during transactions. The malware, delivered via unsigned .NET and Golang installers, intercepts clipboard data to redirect funds to attacker-controlled wallets. Users are advised to verify addresses manually and avoid untrusted extensions.
Meridian48 take
While the attack vector is clever, the real story is how easily browser extensions can bypass Chrome Web Store vetting to steal crypto.
Read the full reporting
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses →
The Hacker News
crypto-clipperbrowser-extension