Jupiter, a DEX (decentralized exchange) aggregator, warned users of a new malware packaged as a Chrome-based extension called Bull Checker.

A new malware, disguised as a Chrome-based extension and named Bull Checker, has been targeting Solana-based DeFi users, leading to their assets being stolen. Jupiter, a DEX (decentralized exchange) aggregator, has warned users about this malicious extension.
The Bull Checker extension was reportedly advertised to show all the holders of any memecoin, and several Solana-based DeFi users encountered their assets being drained after installing the extension. As Jupiter's user base experienced and voiced similar incidents, the DEX aggregator investigated to find the source of the hacks. In an X post, it revealed its findings.
"After extensive investigation, we have identified a malicious Chrome extension called “Bull Checker” that had targeted users on several Solana-related subreddits," the post stated. It further highlighted that those behind the extension advertised the product on Reddit, attempting to lure users by showing how they can make thousands of dollars with the extension.
"Users with this extension would interact with the dApps as per normal, have the simulation show up as normal, but have the possibility of their tokens being maliciously transferred to another wallet upon transaction completion," the post explained. It also added, "If you have this extension (or similar extensions with extensive permissions you cannot trust), please remove it immediately."
Upon installation, Bull Checker asks users for permission to read and change data, which should serve as a warning sign. However, many users might not notice this detail. Extensions that are safe to use typically only ask to read data. By allowing Bull Checker to modify data, it can manipulate recipient addresses on transactions, diverting funds from crypto transfers to a bad actor's wallet.
What's concerning about this malware is that the crypto drainer passes all simulation checks and cannot be detected as a tool developed and used by malicious entities. In a detailed report, Jupiter's pseudonymous founder, known as Meow, wrote, "Bull Checker is supposed to be a read-only extension that allows you to view the holders of memecoins. There should be no need for an extension like this to read or write data on all websites."
The report also includes advice for those interacting with offerings promoted in online communities: "Do not trust something just because someone mentioned it on Reddit or other media and it has many upvotes. Astroturfing and social engineering are very real."
Disclaimer:info@kdj.com
The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!
If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.