Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you installed a Chrome extension masquerading as “Google Notes,” remove it and verify any crypto transaction destination address directly before sending. McAfee Labs reported on June 30, 2026, that a malicious Chromium extension posing as a notes utility could replace copied wallet addresses with attacker-controlled ones. The headline does not identify an extension by name, so Google Notes is a plausible match to the warning—not a confirmed identification.

What the reported extension did

McAfee Labs described a clipboard-swapping attack: the extension watched copy-and-paste activity, recognized copied cryptocurrency wallet addresses, and substituted an attacker-controlled address before the user pasted. A transfer sent to the substituted address may be difficult or impossible to reverse. McAfee said the campaign was distributed through unsigned installers and that the extension masqueraded as “Google Notes.” McAfee Labs’ report does not establish that this is definitively the extension meant by the headline.

What to do if you installed it

  1. Remove the extension. In Chrome, open the extensions manager and uninstall any extension you identify as the impostor. Review other installed extensions too: Google recommends checking whether requested permissions fit an extension’s stated purpose and considering uninstalling extensions whose permissions do not align. Google’s Chrome extension safety guidance explains this check.
  2. Close or refresh pages that were open while it was active. Chromium says injected scripts can continue running in already-open pages until you leave or refresh them. Chromium’s Extensions Security FAQ describes this limitation.
  3. Check for exposure. If you used a wallet or trading site while the extension was installed, review recent activity and follow the official provider’s account or wallet recovery guidance. What steps are appropriate depends on the wallet and what information may have been exposed; the available reporting does not specify a universal recovery procedure.
  4. Verify transaction addresses independently. Before confirming a transfer, compare the destination shown in the transaction with the intended address using a trusted method. Do not rely only on the address currently in the clipboard or on what you pasted.

Uninstalling prevents continued activity by the extension, but it cannot retrieve information already sent elsewhere. Chromium notes that it cannot delete data an extension has already sent from the device to a remote server.

Do not confuse this report with a separate trading-extension campaign

Socket reported a different campaign, published September 9, 2026, involving Chrome and Firefox extensions targeting Axiom Trade and Padre, now Terminal. Socket said those extensions stole session and wallet-related data from authenticated trading sessions, and that four Chrome listings in that campaign had been removed in July 2026. This is not the same reported mechanism as the Google Notes clipboard-address substitution campaign. Socket’s report covers that separate case.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the chance of installing a malicious extension

  • Be wary when an unrelated website urges you to install an extension, particularly if the site and extension have little in common. Google gives this specific warning in its extension safety guidance.
  • Before installing, compare an extension’s requested permissions with what it claims to do. Permissions that seem unrelated to its purpose are a reason to pause and reconsider.
  • Do not treat Chrome Web Store availability as a guarantee. Google reported that less than 1% of all Chrome Web Store installs in 2024 were found to include malware, while acknowledging that malicious extensions can still get through. That historical store-wide figure does not establish whether any particular extension is safe.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.