Maybe you've become a phishing victim and input elsewhere your private keys or json file to that phishing link. If not, that router, it's the first time to hear it although I've used Metamask a few times but didn't have any chance of using it.
Is that another third-party add-on for the wallet that you have downloaded? the possible chance that you've lost it because of it is high.
I have done thorough research on my meatball plugin and there is no record of me connecting to new site nor connecting to metamask swap router, but on Etherscan Approve Checker there is record of metamask swap router.
Well, then you know who's the suspect for the stealing of your funds. Be careful on downloading plugins because there were posts before that everyone should be careful with such. It's a very important thing that you should know what you download and always be doubtful to use it if it's not familiar or popular. I've used Metamask before and it's just smooth but without downloading any other plugins. If the vulnerability is with Metamask, there's no need for you to stay on it, and sad to say that there's no way to get back what was lost to you.
When I check the penetrating address, it is still stealing from other wallet as of 24hours ago. Leaving zero balance ETH on all the victims. Not even a gwei is left.
Whoever is behind it, he will not stop as long as there are possible victims he'll get.