Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Silent Swap Crypto Clipper Exploits Fake Extension

Silent Swap Crypto Clipper Exploits Fake Extension

Posted on June 30, 2026 By CWS

Cybersecurity experts have unveiled a new threat targeting cryptocurrency transactions through a malicious browser extension. Dubbed ‘Silent Swap’ by McAfee Labs, this campaign discreetly alters wallet addresses, posing significant risks to crypto users.

How Silent Swap Operates

The Silent Swap campaign is propagated via unsigned installers in both .NET and Golang versions, deploying a harmful Chromium extension disguised as a legitimate ‘Google Notes’ tool. According to a technical report by McAfee Labs, these installers download a ZIP file that serves as the base for the extension. The extension then scans for Chromium-based browsers, terminating their processes to inject itself by altering secure browser files.

This extension, acting as a clipper, intercepts wallet addresses copied to the clipboard, redirecting funds to a wallet controlled by attackers. To achieve this, it asks users for permissions to access the clipboard, URLs, and browsing history. Given the irreversible nature of blockchain transactions, such swaps can lead to permanent financial losses.

Advanced Evasion Techniques

Silent Swap employs a method known as EtherHiding, utilizing the blockchain as a dead drop resolver to update command-and-control server details. This allows attackers to update server information without redeploying malware. The extension also manipulates protected settings in browsers like Chrome and Edge, enabling developer mode through social engineering to facilitate installation.

By recalculating security verification data, the malware deceives browsers into treating the extension as legitimate. This evasion strategy ensures the extension operates silently, bypassing normal installation processes.

Global Impact and Related Threats

Telemetry data indicates a widespread impact, with significant infection rates in India, the U.S., Brazil, Indonesia, and Spain. This campaign exemplifies the evolution of consumer-targeted crypto theft, moving from static attacker addresses to dynamic, server-side mappings.

In a related disclosure, malicious extensions on Chrome and Firefox, presented as ‘VPN Go: Free VPN,’ have been found to include clipboard stealing capabilities. These extensions not only target wallet addresses but also siphon sensitive data like passwords and authentication codes.

Conclusion and Recommendations

Users are advised to remove any suspicious browser extensions immediately and consider any secrets compromised during their activity. As cyber threats become more sophisticated, vigilance and proactive security measures are essential in protecting digital assets.

The Hacker News Tags:Bitcoin, blockchain security, browser extensions, crypto security, Cybersecurity, Ethereum, fake extensions, McAfee Labs, Silent Swap, Solana, VPN Go, wallet theft

Post navigation

Previous Post: Identifying Breaches: How Tier 1 SOC Analysts Decide
Next Post: Supreme Court: Privacy Rights Cover Cellphone Location Data

Related Posts

Critical SD-WAN Vulnerability and AI Threats Emerge Critical SD-WAN Vulnerability and AI Threats Emerge The Hacker News
SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws SAP Patches Critical NetWeaver (CVSS Up to 10.0) and Previously Exploited S/4HANA Flaws The Hacker News
CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems The Hacker News
MuddyWater’s Espionage Campaign Targets Global Organizations MuddyWater’s Espionage Campaign Targets Global Organizations The Hacker News
Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps The Hacker News
Storm-0501 Exploits Entra ID to Exfiltrate and Delete Azure Data in Hybrid Cloud Attacks Storm-0501 Exploits Entra ID to Exfiltrate and Delete Azure Data in Hybrid Cloud Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Langflow Vulnerability Enables Monero Mining Attacks
  • BioShocking Attack Exposes AI Browsers to Credential Leaks
  • Supreme Court: Privacy Rights Cover Cellphone Location Data
  • Silent Swap Crypto Clipper Exploits Fake Extension
  • Identifying Breaches: How Tier 1 SOC Analysts Decide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Langflow Vulnerability Enables Monero Mining Attacks
  • BioShocking Attack Exposes AI Browsers to Credential Leaks
  • Supreme Court: Privacy Rights Cover Cellphone Location Data
  • Silent Swap Crypto Clipper Exploits Fake Extension
  • Identifying Breaches: How Tier 1 SOC Analysts Decide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark