An app masquerading as DApp MetaMask contained malware that aimed to steal coins by replacing wallet addresses.
The malware, which replaces computer clipboard information in an attempt to steal cryptocurrency, was removed by Google at the beginning of the month after a tip-off from Eset researchers.
Known as a ‘Clipper,’ the malware replaces copied cryptocurrency wallet addresses with an address belonging to an attacker in the hope funds will be sent elsewhere without the user noticing.
The discovery marked the first time such malware had made it past Google’s vetting procedures, the security firm notes.
“The clipper we found lurking in the Google Play store, detected by ESET security solutions as Android/Clipper.C, impersonates a legitimate service called MetaMask,” Eset explained, continuing:
“The malware’s primary purpose is to steal the victim’s credentials and private keys to gain control over the victim’s Ethereum funds. However, it can also replace a Bitcoin or Ethereum wallet address copied to the clipboard with one belonging to the attacker.”
MetaMask, which is one of the oldest Ethereum (ETH)-basd DApps, has fallen victim to malicious schemes before.
In July last year, Google developers pulled the app from Google Play altogether, leaving only fake impersonations. A subsequent report from MetaMask revealed the action had occurred by mistake.
In November, MetaMask confirmed its plans to launch a mobile app, which ended up being the target of the latest malware issue.
Source: , CoinTelegraph
Articles listed with Cash Tech News as the author are either general information, or may have been imported from another website, to bring our readers a rich media experience that encompasses articles that we find interesting, as well as those curated by others.
The views and opinions expressed here are for informational purposes only, and should not be confused with professional financial advice. These opinions are solely those of the author and do not necessarily reflect the views of CashTechNews.com. Every investment and trade involves risk. You should conduct your own research, and contact your professional financial advisor before making any investment.
Corrections, feedback, and ideas should be submitted through the website contact form.