Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Chrome Extension Silently Steal and Injects Hidden SOL Fees Into Solana Swaps

Malicious Chrome Extension Silently Steal and Injects Hidden SOL Fees Into Solana Swaps

Posted on November 27, 2025November 27, 2025 By CWS

A brand new risk has emerged within the Solana buying and selling neighborhood. Safety researchers have found a malicious Chrome extension named Crypto Copilot that seems to supply handy buying and selling options however secretly siphons cryptocurrency from customers throughout transactions.

Printed on the Chrome Internet Retailer on June 18, 2024, the extension has managed to stay out there whereas quietly stealing funds from a whole bunch of merchants who believed they have been utilizing a authentic device.

The extension positions itself as a seamless answer for Solana merchants seeking to execute fast swaps immediately from the X social media platform.

It connects to well-liked wallets like Phantom and Solflare, shows real-time token knowledge from DexScreener, and routes transactions by means of Raydium, one of many largest decentralized exchanges on Solana.

The advertising supplies promise velocity, comfort, and one-click buying and selling with out mentioning any hidden prices or additional transactions.

Socket.dev safety analysts recognized the malicious conduct embedded throughout the extension’s code construction. Behind the engaging interface lies a complicated fee-stealing mechanism that operates with out consumer information.

Each time a consumer performs a swap, the extension injects an undisclosed switch that routes a minimal of 0.0013 SOL or 0.05% of the overall commerce quantity to an attacker-controlled pockets handle: Bjeida13AjgPaUEU9xrh1iQMwxZC7QDdvSfg730xQff7.

Assault Mechanism

The assault works by manipulating transaction development on the blockchain stage. When customers provoke a swap, the extension first builds the authentic Raydium swap instruction.

Then it silently appends a second instruction containing a SystemProgram.switch command that strikes SOL from the consumer’s pockets on to the attacker’s handle.

The consumer interface shows solely the swap particulars, making a false sense of legitimacy. Most pockets affirmation screens present a abstract of transactions with out highlighting particular person directions, so customers signal what seems to be a single transaction whereas each directions execute collectively on-chain.

Crypto Copilot (Supply – Socket.dev)

Socket researchers additionally found extra malicious performance past price theft. The extension exfiltrates customers’ related pockets public keys to a backend server at crypto[.]copilot-dashboard[.]vercel[.]app/api/customers, creating privateness violations.

Moreover, embedded Helius RPC API credentials expose delicate infrastructure data, compounding the safety dangers.

The backend area utilized by the extension crypto-coplilot-dashboard[.]vercel.app hundreds solely a clean placeholder web page, regardless of the extension sending pockets identifiers to its API (Supply – Socket.dev)

The malicious code resides inside property/popup.js file, wrapped in heavy obfuscation to evade detection.

The Chrome Internet Retailer itemizing has remained unchanged regardless of these discoveries, with no warning to potential customers concerning the hidden costs or knowledge assortment occurring within the background.

Observe us on Google Information, LinkedIn, and X to Get Extra Prompt Updates, Set CSN as a Most popular Supply in Google.

Cyber Security News Tags:Chrome, Extension, Fees, Hidden, Injects, Malicious, Silently, SOL, Solana, Steal, Swaps

Post navigation

Previous Post: Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain
Next Post: OpenAI User Data Exposed in Mixpanel Hack

Related Posts

Critical Squid Proxy Vulnerability Exposed with AI Assistance Critical Squid Proxy Vulnerability Exposed with AI Assistance Cyber Security News
CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks CISA Warns of Apple iOS, iPadOS, and macOS 0-day Vulnerability Exploited in Attacks Cyber Security News
PoC Exploit Released for Critical Lua Engine Vulnerabilities PoC Exploit Released for Critical Lua Engine Vulnerabilities Cyber Security News
Adobe Fixes Critical Acrobat Reader Security Flaw Adobe Fixes Critical Acrobat Reader Security Flaw Cyber Security News
Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Cyber Security News
New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark