https://www.bleepingcomputer.com/news/security/first-cryptocurrency-clipboard-hijacker-found-on-google-play-store/
It all begins by downloading an app with malware - on this occasion, a fake metamask app. The article depicts two malware methods used by the app. The former aimed at stealing private keys and seeds of ethereum wallets. The latter is the one really related to the topic here, since the app was capable of monitoring the clipboard for bitcoin and ethereum addresses, and swapping them for those controlled by the attacker.
If this is widespread and still feasible (i.e. no way to patch it) is something I don’t really know, though if there is no way to patch it, likely it's still a thing.