HackMyIP
← Back to News
2026-06-30 The Hacker News

Silent Swap Clipper Hijacks Crypto Wallets via Fake Google Notes Extension

MalwareThreat IntelPrivacy

McAfee Labs has uncovered an active browser extension campaign dubbed Silent Swap that stealthily replaces cryptocurrency wallet addresses during transactions, redirecting funds to attacker-controlled wallets. Delivered through unsigned installers (.NET and Golang variants), the campaign masquerades as a benign "Google Notes" Chromium extension. The .NET installer, named BaseZipInstaller, scans the host for Chromium-based browsers—including Google Chrome, Microsoft Edge, Brave, and Vivaldi—terminates their processes, and injects the malicious extension by tampering with the Secure Preferences and Preferences files.

The extension operates as a clipper, requesting permissions to access the clipboard, all URLs, and browsing history. Once granted, it intercepts copied wallet addresses and substitutes them with addresses controlled by the threat actor. Because blockchain transactions are irreversible, victims face permanent financial loss. What sets Silent Swap apart is its use of EtherHiding, a technique that leverages the blockchain as a dead drop resolver to retrieve active command-and-control server details via smart contract reads. This allows the operator to rotate C2 infrastructure by simply updating a contract value, avoiding malware redeployment. Security professionals tracking similar threats can verify suspicious domains using the WHOIS lookup tool to identify recently registered infrastructure tied to the campaign.

A key evasion tactic involves enabling developer mode through social engineering, after which the malware recalculates the browser's HMAC verification values to make the tampered files appear legitimate—effectively bypassing the standard extension store installation flow. McAfee also tied the activity to the earlier CountLoader campaign, citing overlapping tradecraft and infrastructure. Users concerned about clipboard-level threats should run a browser fingerprint test to audit extensions and configurations, and verify SSL integrity on any site requesting developer privileges via the SSL/TLS checker. The layered persistence and evasion posture signals a deliberate, well-resourced threat actor focused on long-dwell crypto theft rather than opportunistic fraud.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Browser Fingerprint →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a VPN? →How websites track you →Browser fingerprinting explained →