BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious VS Code Extension Solidity Pro Steals Wallets, Credentials

Malicious VS Code extension Solidity Pro steals crypto wallets, seed phrases, evades detection via obfuscation.

  • Malicious VS Code extension “Solidity Pro” steals browser crypto wallets and credentials
  • Captures seed phrases, GitHub tokens, AWS keys, OpenAI keys, and SSH private keys
  • Uses obfuscation, clean intermediate versions, and delayed activation to evade detection
  • Shares its playbook with the WhiteCobra cluster linked to Lumma Stealer
  • Users are urged to remove the extension and inspect dependency graphs

Cybersecurity researchers on Aug 10, 2026 flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that delivers a browser wallet and credential stealer. The extensions, helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, are no longer available on Open VSX, though the GitHub repository remains accessible.

- Advertisement -

According to a report from Yeeth Security, early iterations from v1.0.0 through v2.4.x beaconed to Cloudflare Workers endpoints to retrieve and execute an encrypted Python payload. Subsequent versions starting with v3.0.0 shifted to a full-blown information stealer that collects browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens, exfiltrating data via a Telegram bot upload.

The harvested data includes GitHub ghp_ and github_pat_ tokens, GitLab glpat- tokens, AWS keys, Cloudflare cfat_ tokens, OpenAI sk-, sk-proj-, and sk-ant- keys, Telegram bot tokens, mnemonic seed phrases, and wallet vaults from MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr. It also targets Bitcoin WIF/xprv keys, SSH private keys, URL credentials, and 1Password MFA tokens.

The malware family evades marketplace review through heavy obfuscation, intermediate clean versions, and randomized delayed activation. “By the time the malicious branch runs, the user has already decided the extension is useful, and automated scanners that only observe the package for minutes have moved on,” Yeeth Security said.

The activity shares the same high-level playbook as WhiteCobra, a threat cluster detected in September 2025 distributing Lumma Stealer via malicious VS Code extensions. In June 2026, Yeeth Security flagged another extension, ethdevtools.solidity-language-support, which impersonated a Solidity language-support tool but harbored a delayed-activation clipboard stealer that scrapes BIP-39 seed phrases and Ethereum private keys.

- Advertisement -

The findings also coincide with the discovery of rogue npm packages and VS Code extensions, including an npm package called ascii-fetcher, which embeds malicious code in a dependency named @jaymara/jsononifier. Other discoveries include 10 VS Code extensions delivering Windows-based droppers and DigitalBarberTrim.html-entity-codec, which drops a remote VSIX file after enumerating VS Code forks.

Users who installed the extensions are advised to remove them, inspect dependency graphs, and block known C2 domains.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Cronos halts network after $75M Tectonic exploit

Cronos halted its blockchain after an exploit targeting Tectonic involved an estimated $75 millioncrypto.com...

PayPal Down 13% as Advent, Stripe Drop Bid; Retail Bullish

Paypal stock plunged nearly 13% last week after reports that Advent and Stripe abandoned...

Polygon Labs quietly fixes critical security bugs with hard forks

Polygon Labs disclosed it patched a batch of security vulnerabilities through two hard forks...

Saylor Signals ‘We’re Back’ as Strategy Set to Resume Bitcoin Buys

Strategy co-founder Michael Saylor posted a cryptic message on X, signaling the company's likely...

India pitches CBDC link for BRICS trade at upcoming summit

India will propose a central bank digital currency (CBDC) linkage at the BRICS summit...

Must Read

The Ultimate Guide on How to Understand a Cryptocurrency White Paper

Today, cryptocurrency is a popular buzzword. We hear about it on the news, we read about it on the Internet. Yet, people are reluctant to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading