[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWGTeCxEm4cENuUK2StLHCRGWgEBVWdXWRkxjpbf2ANQ":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"2309062b-497b-4b4d-b842-a143083666e6","Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials","solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials-434107","Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (\"solidity-pro\") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository","Cybersecurity researchers have identified malicious VS Code extensions, branded as 'Solidity Pro', designed to steal sensitive information including crypto wallets, API keys, and credentials. Early versions delivered an encrypted Python payload, while later versions evolved into a full information stealer exfiltrating data via Telegram. The malware employs heavy obfuscation and delayed activation to evade detection.","Malicious VS Code extensions named Solidity Pro steal crypto wallets and API keys.","Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials Ravie LakshmananAug 10, 2026Malware \u002F Cybercrime Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (\"solidity-pro\") that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository for \"web3devtoolsx\u002Fsolidity-pro\" continues to remain accessible as of writing. According to Yeeth Security, early iterations of the extensions – from 1.0.0 through v2.4.x – were found to beacon to Cloudflare Workers endpoints to retrieve an encrypted Python payload and execute it. Subsequent versions starting with v3.0.0, on the other hand, have shifted to a full-blown information stealer that can collect browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. The captured data is then exfiltrated via a Telegram bot upload. The list of data harvested by the stealer is as follows - GitHub ghp_ and github_pat_ tokens GitLab glpat- tokens AWS keys and session tokens Cloudflare cfat_ tokens OpenAI sk-, sk-proj-, and sk-ant- keys Telegram bot tokens Mnemonic and seed phrases MetaMask, Phantom, Rabby, Coinbase, Trust, Keplr wallet vaults Bitcoin WIF \u002F xprv SSH private keys (PRIVATE KEY) URL credentials and 1Password MFA tokens The malware family is also equipped to bypass marketplace review, static scanning, and casual sandboxing through heavy obfuscation, intermediate clean versions to build trust, and randomized delayed activation that causes the malicious code to run several hours or days after installation. \"By the time the malicious branch runs, the user has already decided the extension is useful, and automated scanners that only observe the package for minutes have moved on,\" Yeeth Security said. \"The obfuscation is not decorative; it splits strings across IIFE tables, reassembles them at runtime, and switches method names between releases so signature-based detection must track a moving target.\" The cybersecurity company said the activity shares the same high-level playbook as WhiteCobra, another threat cluster that was detected in September 2025 as distributing Lumma Stealer through malicious VS Code extensions. This is not the first time threat actors have published bogus Solidity extensions across open-source ecosystems. In June 2026, Yeeth Security flagged another extension named \"ethdevtools.solidity-language-support\" that impersonated a Solidity language-support tool for Ethereum developers, but harbored a delayed-activation clipboard stealer to scrape BIP-39 seed phrases, Ethereum private keys, and wallet addresses. \"When a recognized crypto address is on the clipboard, it replaces the pasted value with an attacker-controlled address,\" it added. \"The swap happens through vscode.env.clipboard.writeText, a first-party API call that requires no child_process, no network access, and no file writes. Static scanners that only look for dangerous Node imports will not see it.\" The findings also coincide with the discovery of a number of rogue VS Code extensions and npm packages - An npm package called \"ascii-fetcher,\" which embeds the malicious code in a dependency named \"@jaymara\u002Fjsononifier\" to decode an embedded command (in the observed case, \"calc.exe\") and run it via \"child_process.exec\" with \"windowsHide\" A set of 10 VS Code extensions that deliver a wide range of Windows-based BAT, JavaScript, and HTA droppers, with two of them bundling an npm dependency that uses a postinstall hook to fetch and execute a remote payload A VS Code extension named \"DigitalBarberTrim.html-entity-codec\" that drops a remote VSIX file in select versions after enumerating known VS Code forks like Cursor, Windsurf, Codium, and Positron, while serving a \"nearly empty stub\" in others to fly under the radar. Users who have installed the extensions are advised to remove them, inspect dependency graphs, block known command-and-control (C2) domains, and alert on use of cscript, mshta, cmd, curl, and powershell commands. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Cloud security, Credential Theft, cryptocurrency, Cybercrime, Developer Security, Information Stealer, Malware, Open Source, Software Supply Chain ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fsolidity-pro-vs-code-extensions-steal.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjR5_Dx4heVYIxaujo8ybl0OFdVuLzMFe0qdEdr6-q_QTdhSVlgHdrP6MeooXamFpRNfHjoAqTquvk3CkkCKUw1TQDkQJCrZY1RTC9iYK_bsTLNvpj0BZfFKFcnlt1RAlBvfcsWeSuLAn6Gwh9lur7v9-HlH-6ZpSmw7npsn9TSZAEpwFSFE54_xcFPcuDi\u002Fs1600\u002Fpro.jpg","2026-08-10T07:38:23+00:00","2026-08-10T10:00:18.717126+00:00",9,[18,21,23,26,29],{"name":19,"type":20},"Solidity Pro","product",{"name":22,"type":20},"Visual Studio Code",{"name":24,"type":25},"Microsoft","vendor",{"name":27,"type":28},"WhiteCobra","threat_actor",{"name":30,"type":20},"Lumma Stealer","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":31,"icon":33,"name":34,"slug":35},null,"Malware","malware",[37,42,44,49],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":43},{"id":31,"icon":33,"name":34,"slug":35},{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55,59,61,64],{"type":56,"value":57,"context":58},"url","https:\u002F\u002Fgithub.com\u002Fweb3devtoolsx\u002Fsolidity-pro","GitHub repository for one of the malicious extensions.",{"type":35,"value":30,"context":60},"Similar playbook observed with threat cluster WhiteCobra distributing Lumma Stealer.",{"type":35,"value":62,"context":63},"clipboard stealer","Another malicious extension 'ethdevtools.solidity-language-support' used a clipboard stealer.",{"type":35,"value":65,"context":66},"BAT, JavaScript, and HTA droppers","Other malicious VS Code extensions deliver these types of payloads."]