Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Malicious Solidity Pro VS Code extensions are targeting developers to steal cryptocurrency wallets, API keys, and sensitive credentials.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A new security threat has emerged involving fake Solidity Pro extensions for Visual Studio Code that function as credential-stealing malware. According to coverage from The Hacker News and gbhackers.com, these malicious extensions are specifically designed to target developer tooling. Once installed, the extensions act as a gateway for stealing cryptocurrency wallets, API keys, and other private credentials from the victim's system. This attack leverages the trust developers place in their integrated development environment extensions to gain unauthorized access to sensitive data. Technical analysis provided by cyberpress.org emphasizes a specific delivery mechanism where the malicious extension drops a detached Python payload.
This payload is executed outside of the standard extension host, a tactic likely used to evade detection by security software that monitors the VS Code process. Further reporting from Korben confirms the presence of these malicious VS Code extensions, highlighting the risk to users who install unverified tooling. The combined coverage from these four sources paints a picture of a targeted campaign aimed at the blockchain development community. By masquerading as a 'Pro' version of a Solidity tool, the attackers target high-value individuals who likely possess access to crypto wallets and critical API keys for cloud infrastructure or blockchain services. The ability to steal these credentials can lead to direct financial loss or the compromise of larger software projects, making the security of the developer's local environment a critical point of failure.
Future monitoring will focus on the identification of the specific fake extensions currently available in the marketplace and the behavior of the detached Python payload. Based on the reports from gbhackers.com and The Hacker News, the primary concern remains the continued distribution of these credential-stealing tools. Users are encouraged to verify the authenticity of their VS Code extensions. Coverage does not yet specify if the official Visual Studio Code marketplace has removed these specific extensions or if a wider list of compromised tool names has been compiled by security researchers.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (93% supported) Updated 11h ago.
Quick answers
What exactly are the Solidity Pro extensions stealing?
The extensions are designed to steal cryptocurrency wallets, API keys, and other sensitive credentials.
How does the malware avoid detection in VS Code?
According to cyberpress.org, the extension drops a detached Python payload that runs outside the extension host.
Who is the primary target of this malware?
The malware targets developers using Visual Studio Code who utilize Solidity tooling for smart contract development.
Coverage (4)
- Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware gbhackers.com · 2d ago
- Malicious VS Code extensions Korben · 2d ago
- Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host cyberpress.org · 2d ago
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials The Hacker News · 2d ago
Topics
Related trends
SEC Poised to Unveil Major Crypto Plans as Clarity Act Stalls
The SEC may introduce pivotal cryptocurrency rules featuring a token safe harbor as legislative progress on the Clarity Act remains stalled.
As Trump Media scraps some businesses, it's doubling down on Truth Social and the president
Trump Media is pivoting its corporate strategy to focus on Truth Social and the president amid significant quarterly financial losses.
The Complicated Case of Passing On Your Digital Estate
The rise of crypto and virtual assets is forcing a critical rethink of digital estate planning and asset division during legal separations.
Hackers Figure Out a Trick to Steal Bitcoin From Cold Wallets, Grab $110 Million
A sophisticated exploit targeting Coldcard cold wallets has resulted in the theft of over $110 million in Bitcoin, challenging the security of self-custody.
US sanctions Dubai crypto exchange for aiding Iran's IRGC, following a Reuters report
The US has sanctioned Dubai-based crypto exchange Shelbit for allegedly facilitating $6.3 billion for Iran's IRGC and illicit economy.
ClickFix attack pushes macOS infostealer for crypto theft attacks
A new wave of ClickFix attacks targets macOS users with fake CAPTCHAs to deploy infostealers designed to drain cryptocurrency wallets.