Malicious Chrome Extension Silently Steal and Injects Hidden SOL Fees Into Solana Swaps
ID: 263eca3a-a829-54f0-b4db-5d68ac9df5e9
STIX ID: report--263eca3a-a829-54f0-b4db-5d68ac9df5e9
Feed Name: cybersecurityNews.com
A malicious Chrome extension named Crypto Copilot, published to the Chrome Web Store on June 18, 2024, targeted Solana traders by injecting hidden SOL transfer instructions into Raydium swap transactions (stealing at least 0.0013 SOL or 0.05% per trade) and exfiltrating wallet public keys to a backend; Socket.dev analysis identifies the attacker address (Bjeida13AjgPaUEU9xrh1iQMwxZC7QDdvSfg730xQff7), the malicious code in assets/popup.js, obfuscation, and exposed Helius RPC credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
