Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
AI-summarised brief · reviewed before publication
Cybersecurity firm Yeeth Security has identified a malicious Visual Studio Code extension called Solidity Pro that harvests crypto wallets, API keys, SSH keys, source‑control tokens and Telegram bot tokens. Early versions (1.0.0‑2.4.x) fetched an encrypted Python payload from Cloudflare Workers, while versions from 3.0.0 onward act as a full‑blown stealer, exfiltrating data through a Telegram bot. The malware evades marketplace review and static analysis by using heavy obfuscation, clean interim releases to build trust, and delayed activation that can wait days before executing. The extension remains downloadable from its GitHub repo despite removal from Open VSX. Yeeth notes the campaign mirrors the WhiteCobra threat cluster that previously distributed the Lumma stealer via rogue VS Code extensions, and it follows a pattern of fake Solidity tools targeting developers.
💡 Why It Matters
- · By compromising a development tool trusted by blockchain programmers, the attack gives threat actors direct access to high‑value crypto assets and infrastructure credentials, turning everyday coding environments into covert data‑exfiltration channels.