Silent Swap browser-extension clipboard clipper
Malware Activity
Summary
Hide ▲
Show ▼
The Silent Swap malware activity now installs malicious Chromium extensions that intercept copied wallet addresses and reroute cryptocurrency transfers to attacker-controlled wallets, creating direct financial-loss risk for affected users. The activity also steals other clipboard-derived secrets and hides behind a benign-looking Google Notes extension. It uses unsigned .NET and Golang installers and browser tampering to load silently across Chromium-based browsers.
Related Happenings
Opera GX silent mod-install XS-Leak security flaw
Vulnerability
H score19
First: 06.07.2026 10:27
Last: 06.07.2026 10:27
Sources 1
About this happening:
Opera GX had a flaw in its GX Mods install path that let a malicious website silently install a browser add-on and leak data from visited pages, creating no-click ex...
Opera GX silent mod-install XS-Leak security flaw
VulnerabilityAbout this happening: Opera GX had a flaw in its GX Mods install path that let a malicious website silently install a browser add-on and leak data from visited pages, creating no-click ex...
Silent Swap browser-extension crypto-theft campaign
Campaign
H score36
First: 30.06.2026 18:40
Last: 30.06.2026 18:40
Sources 1
How related:
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction.
About this happening:
The Silent Swap campaign is replacing copied cryptocurrency wallet addresses with attacker-controlled ones, creating a risk of permanent financial loss for crypto users. I...
Silent Swap browser-extension crypto-theft campaign
CampaignHow related: Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction.
About this happening: The Silent Swap campaign is replacing copied cryptocurrency wallet addresses with attacker-controlled ones, creating a risk of permanent financial loss for crypto users. I...
Search for perplexity ai malicious Chrome extension
Malware Activity
H score29
First: 29.06.2026 21:40
Last: 29.06.2026 21:40
Sources 1
About this happening:
A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Search for perplexity ai malicious Chrome extension
Malware ActivityAbout this happening: A malicious Chrome extension named Search for perplexity ai impersonated Perplexity AI while intercepting search traffic and collecting browsing information th...
Dormant remote-controlled JavaScript injection path in Adblock for YouTube Chrome extension
Technical Analysis
H score23
First: 25.06.2026 17:12
Last: 25.06.2026 17:12
Sources 1
About this happening:
A Chrome extension with 10 million+ installs was found to carry a dormant script-injection path, raising the risk of arbitrary JavaScript execution across visited...
Dormant remote-controlled JavaScript injection path in Adblock for YouTube Chrome extension
Technical AnalysisAbout this happening: A Chrome extension with 10 million+ installs was found to carry a dormant script-injection path, raising the risk of arbitrary JavaScript execution across visited...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Timeline
-
30.06.2026 18:40 2 articles · 15d ago
Silent Swap browser extension replaces copied wallet addresses
Initial DisclosureMcAfee Labs flagged Silent Swap, an active browser-extension campaign that uses unsigned .NET and Golang installers to deploy a malicious Chromium extension masquerading as Google Notes. The extension intercepts wallet addresses copied into the clipboard and replaces them with attacker-controlled values to divert cryptocurrency, while EtherHiding is used to resolve active C2 details and browser preference-file tampering helps the extension persist and load silently across Chromium-based browsers. Telemetry indicates infections are globally distributed, with a higher concentration in India and additional victims in the U.S., Brazil, Indonesia, and Spain.
Show sources
- Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses — thehackernews.com — 30.06.2026 18:40
- Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses — thehackernews.com — 30.06.2026 18:40