Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
AI Generated Image

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

The Hacker News technology

Key Points:

  • Cybersecurity researchers have identified malicious Visual Studio Code extensions named "helper-beeps.solidity-pro" and "web3devtoolsx.solidity-pro" that steal browser wallets, credentials, and sensitive tokens from users.
  • Early versions of these extensions downloaded encrypted Python payloads, while later versions evolved into sophisticated information stealers capturing data such as GitHub tokens, crypto wallets, API keys, SSH keys, and Telegram bot tokens, exfiltrated via Telegram bots.
  • The malware uses heavy obfuscation, delayed activation, and intermediate clean versions to evade detection by automated scanners and marketplace reviews, allowing it to operate undetected for days after installation.
  • This campaign resembles previous attacks like the WhiteCobra cluster distributing Lumma Stealer via malicious VS Code extensions, and follows a pattern of fake Solidity-related tools targeting Ethereum developers.
  • Users who installed these extensions are urged to uninstall them, review dependencies, block known command-and-control domains, and monitor for suspicious command-line activities involving cscript, mshta, cmd, curl, and powershell.

Trending Business

Trending Technology

Trending Health