Security researchers have uncovered a malicious Chrome extension named Crypto Copilot that secretly imposes additional fees on Raydium swap transactions. The extension adds hidden SOL transfers, charging users between 0.0013 SOL and 0.05% of the transaction amount without their knowledge. Despite requests for its removal, the extension remains active, connecting to legitimate wallets and DexScreener data. This incident underscores the security vulnerabilities associated with browser-based trading tools that demand extensive signature permissions.