importantSYS.SOURCE: The Hacker News• 2026-08-10T13:08:23+05:30
Malicious Solidity Pro VS Code Extensions Exfiltrate Sensitive Data and Credentials
Malicious Solidity Pro VS Code extensions steal crypto wallets, API keys, and credentials via Telegram bot exfiltration. The malware employs advanced obfuscation and delayed activation to evade detection, targeting developer tools and open-source ecosystems.
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer.
The names of the extensions are below -
helper-beeps.solidity-pro web3devtoolsx.solidity-pro
Although neither of the extensions is now available on Open VSX, the GitHub repository
*** END OF TRANSMISSION ***