What Is Silent Swap: The Attack Your Credentials Never See Coming
Silent Swap is an attack technique where a seemingly legitimate Chrome extension receives a silent update that activates malicious code to intercept and exfiltrate API keys, OAuth tokens, and environment variables directly from the browser — no alerts, no log traces, no antivirus detection. The original extension is real and useful; the trap arrives weeks or months later, once it has consolidated permissions. Chrome updates extensions silently in the background without notifying the user. By the time the security team detects the incident, the secrets have been leaking for days.