


Perceptive Security
SOC/SIEM Consultancy

Socket researchers identified a malicious Chrome extension that manipulates Raydium swaps to inject an undisclosed SOL transfer, quietly routing fees to an atta…
Published:
25 november 2025 om 17:43:50
Alert date:
5 december 2025 om 08:03:23
Source:
socket.dev

Socket researchers discovered a malicious Chrome extension that targets Solana cryptocurrency users by manipulating Raydium swap transactions. The extension injects hidden SOL transfer fees into legitimate swap operations without user knowledge. The malicious fees are secretly routed to an attacker-controlled wallet address. This represents a supply chain attack targeting cryptocurrency users through browser extensions. The attack demonstrates sophisticated financial fraud techniques in the DeFi ecosystem.
Technical details
Mitigation steps:
Affected products:
Chrome Extensions
Raydium
Solana
Related links:
https://socket.dev/blog/malicious-chrome-extension-injects-hidden-sol-fees-into-solana-swaps?utm_medium=feed
https://socket.dev/chrome/package/iaemdpdnmdkaphnmcogmcgcmhhafcifd/overview/1.1.0
Related CVE's:
Related threat actors:
IOC's:
iaemdpdnmdkaphnmcogmcgcmhhafcifd
This article was created with the assistance of AI technology by Perceptive.