SECURITYTHE HACKER NEWS
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro"). This extension was observed delivering a browser wallet and credential stealer. The specific extensions identified as malicious include helper-beeps.solidity-pro and web3devtoolsx.solidity-pro.
Mentioned
Related Signal
Adjacent reporting
- Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
- GitHub Confirms 3,800 Internal Repos Stolen Through Poisoned VS Code Extension
- GitHub says internal repositories were taken in poisoned VS Code extension attack
- GitHub confirms breach of 3,800 repos via malicious VSCode extension
- GitHub says internal repos exfiltrated after poisoned VS Code extension attack
- Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer