Silent Swap crypto clipper swaps wallet addresses via fake Google Notes extension
Source headline: Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
Intelligence Summary
McAfee Labs says the Silent Swap campaign uses a stealthy browser extension to alter crypto recipient addresses during transactions. The extension is distributed via unsigned installer packages. Observed variants include .NET and Golang builds. Users who install the fake Google Notes add-on may unknowingly send funds to attacker-controlled wallets. Wallet-address replacement malware like this can cause irreversible losses, so users should avoid untrusted extensions and verify extension sources and wallet addresses before confirming payments.
Recommended Action
Inventory where Silent Swap runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.