Rust-based clipboard hijacker swapping cryptocurrency addresses via Binance Smart Chain
Malware Activity
Summary
Hide ▲
Show ▼
A Rust-based clipboard hijacker was observed swapping copied cryptocurrency wallet addresses with attacker-controlled destinations, putting payment workflows across 21 blockchain types at risk. The malware used Binance Smart Chain for command-and-control resolution through EtherHiding. A victim could still see a normal-looking transaction even though the destination had already been changed locally before signing.
Related Happenings
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker that swaps wallet addresses
Malware Activity
H score10
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...
Rust-based clipboard hijacker that swaps wallet addresses
Malware ActivityAbout this happening: The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...
GhostLoader staged npm install payload activity
Malware Activity
H score30
First: 24.03.2026 14:00
Last: 24.03.2026 14:00
Sources 1
About this happening:
GhostLoader is now being delivered through staged npm install scripts, turning routine package installation into a route for data theft and cryptocurrency wallet t...
GhostLoader staged npm install payload activity
Malware ActivityAbout this happening: GhostLoader is now being delivered through staged npm install scripts, turning routine package installation into a route for data theft and cryptocurrency wallet t...
Timeline
-
07.08.2026 17:00 2 articles · 3h ago
Rust-based clipboard hijacker swapping cryptocurrency addresses via Binance Smart Chain
Initial DisclosureThe first stage watched clipboard contents for cryptocurrency address patterns and swapped any supported match before the paste reached a wallet or exchange. It then resolved command-and-control pointers through Binance Smart Chain, adding a mutable lookup layer to the operation.
Show sources
- Real emails, hijacked payments: Two H1 2026 attack chains — www.bleepingcomputer.com — 07.08.2026 17:00
- Real emails, hijacked payments: Two H1 2026 attack chains — www.bleepingcomputer.com — 07.08.2026 17:00