Threats · 76 days ago
The trust break happens before the browser ever checks the extension. A malicious installer edits Chromium profile files so a fake add-on appears already approved, which means store vetting and user caution never get a chance to help.
McAfee says Silent Swap is using unsigned .NET and Golang installers to push a bogus “Google Notes” Chromium extension across Chrome, Edge, Brave, and Vivaldi profiles. The extension watches copied wallet addresses, swaps them, and can proxy browser traffic; the campaign also uses blockchain-based C2 updates.
That leaves local software execution and profile integrity as the real control point. If untrusted installers can run on an endpoint, browser extension governance alone does not stop persistent clipper activity across affected profiles.
1 source covering this story
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
McAfee says the campaign uses unsigned .NET and Golang installers, EtherHiding C2, and silent Chromium extension injection to swap wallet addresses.
Part of the PlainSec briefing for 2026-06-30