XRP and BTC Among Coins Targeted in New Malware Campaign
Cybersecurity researchers at McAfee uncovered “Silent Swap,” a sophisticated crypto-stealing malware campaign that sideloads a fake Google Notes extension into Chromium browsers. The malware targets users who copy wallet addresses for Bitcoin, Ethereum, XRP, Bitcoin Cash, Dash and other coins, then replaces them with attacker-controlled addresses via clipboard interception and server-side wallet mapping. It uses advanced browser manipulation, configuration tampering, decentralized C2 infrastructure and EtherHiding to avoid static command-and-control domains. The article is a security warning rather than a market-moving crypto catalyst, but it underscores ongoing operational risks for crypto holders and could reinforce caution around wallet transfers and browser extensions.