Installer Abuse Bypasses Chromium Extension Trust

The trust break happens before the browser ever checks the extension. A malicious installer edits Chromium profile files so a fake add-on appears already approved, which means store vetting and user caution never get a chance to help. McAfee says Silent Swap is using unsigned .NET and Golang installers to push a bogus “Google Notes” Chromium extension across Chrome, Edge, Brave, and Vivaldi profiles. The extension watches copied wallet addresses, swaps them, and can proxy browser traffic; the campaign also uses blockchain-based C2 updates. That leaves local software execution and profile integrity as the real control point. If untrusted installers can run on an endpoint, browser extension governance alone does not stop persistent clipper activity across affected profiles.

Part of the PlainSec briefing for 2026-06-30

Sources