[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLcWdhEq3X2gR8MmionigkkHT2vcIqrqZkDBsE5aj3n4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"f6f949fb-3a04-4dff-95c2-08df30d40bd6","malicious-vs-code-extensions-masquerade-as-solidity-tools-to-steal-crypto-and-credentials","2309062b-497b-4b4d-b842-a143083666e6","Malicious VS Code Extensions Masquerade as Solidity Tools to Steal Crypto and Credentials","Threat actors published fake 'Solidity Pro' extensions to the VS Code marketplace, weaponizing a trusted developer toolchain to deliver an information-stealing payload that exfiltrates crypto wallets, API keys, and credentials via Telegram. The attack exploits developer trust in extension marketplaces, where code is often installed without rigorous vetting. Heavy obfuscation and delayed activation allowed the malware to evade initial detection, prolonging the window of data exfiltration. This incident highlights the growing risk of software supply chain attacks targeting developer environments, where a single malicious dependency or extension can compromise entire projects and secrets. Organizations that allow unmanaged extension installation face significant exposure to credential theft and downstream compromise.","**Immediate actions:**\n- Audit all installed VS Code extensions across developer workstations and remove any unverified or suspicious packages immediately.\n- Rotate all API keys, crypto wallet credentials, and secrets stored on systems where malicious extensions may have been installed.\n- Block outbound Telegram API endpoints (api.telegram.org) at the network perimeter to disrupt common malware exfiltration channels.\n\n**Long-term improvements:**\n- Enforce an approved extension allowlist policy so developers can only install pre-vetted VS Code extensions from a curated internal registry.\n- Implement secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager) so credentials are never stored in plaintext on developer machines.\n- Integrate IDE and developer tooling into your software supply chain security program with periodic third-party reviews.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools capable of identifying obfuscated Python payloads and anomalous process executions spawned by editor processes.\n- Monitor and alert on unexpected outbound network connections originating from IDE processes or developer workstations.\n- Establish baseline behavioral monitoring for developer environments to detect delayed-activation malware that bypasses initial scans.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 10: Malware Defenses","CIS Control 13: Network Monitoring and Defense","NIST SP 800-161: Cyber Supply Chain Risk Management","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 IA-5: Authenticator Management","NIST CSF ID.SC-4: Supply Chain Risk Assessment","SLSA Supply Chain Levels for Software Artifacts (Framework)","GDPR Article 32: Security of Processing (for EU orgs handling personal data via compromised credentials)","published","2026-08-10T10:21:24.08111+00:00","2026-08-10T10:21:23.781+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fsolidity-pro-vs-code-extensions-steal.html","solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials-434107","Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"5b25dd90-1411-4cd1-b545-7d876920b08b","2026-08-10","afternoon","ThreatNoir Afternoon Brief — August 10","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-10\u002Fthreatnoir-afternoon-brief-2026-08-10.mp3"]