- Malicious VS Code extension “Solidity Pro” steals browser crypto wallets and credentials
- Captures seed phrases, GitHub tokens, AWS keys, OpenAI keys, and SSH private keys
- Uses obfuscation, clean intermediate versions, and delayed activation to evade detection
- Shares its playbook with the WhiteCobra cluster linked to Lumma Stealer
- Users are urged to remove the extension and inspect dependency graphs
Cybersecurity researchers on Aug 10, 2026 flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that delivers a browser wallet and credential stealer. The extensions, helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, are no longer available on Open VSX, though the GitHub repository remains accessible.
According to a report from Yeeth Security, early iterations from v1.0.0 through v2.4.x beaconed to Cloudflare Workers endpoints to retrieve and execute an encrypted Python payload. Subsequent versions starting with v3.0.0 shifted to a full-blown information stealer that collects browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens, exfiltrating data via a Telegram bot upload.
The harvested data includes GitHub ghp_ and github_pat_ tokens, GitLab glpat- tokens, AWS keys, Cloudflare cfat_ tokens, OpenAI sk-, sk-proj-, and sk-ant- keys, Telegram bot tokens, mnemonic seed phrases, and wallet vaults from MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr. It also targets Bitcoin WIF/xprv keys, SSH private keys, URL credentials, and 1Password MFA tokens.
The malware family evades marketplace review through heavy obfuscation, intermediate clean versions, and randomized delayed activation. “By the time the malicious branch runs, the user has already decided the extension is useful, and automated scanners that only observe the package for minutes have moved on,” Yeeth Security said.
The activity shares the same high-level playbook as WhiteCobra, a threat cluster detected in September 2025 distributing Lumma Stealer via malicious VS Code extensions. In June 2026, Yeeth Security flagged another extension, ethdevtools.solidity-language-support, which impersonated a Solidity language-support tool but harbored a delayed-activation clipboard stealer that scrapes BIP-39 seed phrases and Ethereum private keys.
The findings also coincide with the discovery of rogue npm packages and VS Code extensions, including an npm package called ascii-fetcher, which embeds malicious code in a dependency named @jaymara/jsononifier. Other discoveries include 10 VS Code extensions delivering Windows-based droppers and DigitalBarberTrim.html-entity-codec, which drops a remote VSIX file after enumerating VS Code forks.
Users who installed the extensions are advised to remove them, inspect dependency graphs, and block known C2 domains.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- US Inflation Data Looms Wednesday as Fed Rate Decision Awaited
- Bitcoin researcher forced to Chinese AI after OpenAI blocks access
- United Boeing 787 Elevated Adds Houston Long-Haul New Routes
- Elon Musk: SpaceX V3 Starlink Satellites Will Deliver 100x V2 Bandwidth
- Ex-US defense chief: CLARITY Act is national security, not just finance.
