Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silent Swap Crypto Clipper Exploits Fake Extension

Silent Swap Crypto Clipper Exploits Fake Extension

Posted on June 30, 2026 By CWS

Cybersecurity experts have unveiled a new threat targeting cryptocurrency transactions through a malicious browser extension. Dubbed ‘Silent Swap’ by McAfee Labs, this campaign discreetly alters wallet addresses, posing significant risks to crypto users.

How Silent Swap Operates

The Silent Swap campaign is propagated via unsigned installers in both .NET and Golang versions, deploying a harmful Chromium extension disguised as a legitimate ‘Google Notes’ tool. According to a technical report by McAfee Labs, these installers download a ZIP file that serves as the base for the extension. The extension then scans for Chromium-based browsers, terminating their processes to inject itself by altering secure browser files.

This extension, acting as a clipper, intercepts wallet addresses copied to the clipboard, redirecting funds to a wallet controlled by attackers. To achieve this, it asks users for permissions to access the clipboard, URLs, and browsing history. Given the irreversible nature of blockchain transactions, such swaps can lead to permanent financial losses.

Advanced Evasion Techniques

Silent Swap employs a method known as EtherHiding, utilizing the blockchain as a dead drop resolver to update command-and-control server details. This allows attackers to update server information without redeploying malware. The extension also manipulates protected settings in browsers like Chrome and Edge, enabling developer mode through social engineering to facilitate installation.

By recalculating security verification data, the malware deceives browsers into treating the extension as legitimate. This evasion strategy ensures the extension operates silently, bypassing normal installation processes.

Global Impact and Related Threats

Telemetry data indicates a widespread impact, with significant infection rates in India, the U.S., Brazil, Indonesia, and Spain. This campaign exemplifies the evolution of consumer-targeted crypto theft, moving from static attacker addresses to dynamic, server-side mappings.

In a related disclosure, malicious extensions on Chrome and Firefox, presented as ‘VPN Go: Free VPN,’ have been found to include clipboard stealing capabilities. These extensions not only target wallet addresses but also siphon sensitive data like passwords and authentication codes.

Conclusion and Recommendations

Users are advised to remove any suspicious browser extensions immediately and consider any secrets compromised during their activity. As cyber threats become more sophisticated, vigilance and proactive security measures are essential in protecting digital assets.

The Hacker News Tags:Bitcoin, blockchain security, browser extensions, crypto security, Cybersecurity, Ethereum, fake extensions, McAfee Labs, Silent Swap, Solana, VPN Go, wallet theft

Post navigation

Previous Post: Identifying Breaches: How Tier 1 SOC Analysts Decide
Next Post: Supreme Court: Privacy Rights Cover Cellphone Location Data

Related Posts

The Case for Dynamic AI-SaaS Security as Copilots Scale The Case for Dynamic AI-SaaS Security as Copilots Scale The Hacker News
China-Linked JDY Botnet Expands to Over 1,500 Devices China-Linked JDY Botnet Expands to Over 1,500 Devices The Hacker News
Meta Expands WhatsApp Security Research with New Proxy Tool and M in Bounties This Year Meta Expands WhatsApp Security Research with New Proxy Tool and $4M in Bounties This Year The Hacker News
Microsoft Fixes 84 Security Flaws, Including Two Zero-Days Microsoft Fixes 84 Security Flaws, Including Two Zero-Days The Hacker News
Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware The Hacker News
SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Majority of iOS AI Apps Expose Vulnerable API Keys
  • Critical AirDrop and Quick Share Flaws Expose Devices
  • Critical Oracle E-Business Suite Flaw Exploited
  • Langflow Vulnerability Enables Monero Mining Attacks
  • BioShocking Attack Exposes AI Browsers to Credential Leaks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Majority of iOS AI Apps Expose Vulnerable API Keys
  • Critical AirDrop and Quick Share Flaws Expose Devices
  • Critical Oracle E-Business Suite Flaw Exploited
  • Langflow Vulnerability Enables Monero Mining Attacks
  • BioShocking Attack Exposes AI Browsers to Credential Leaks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark