Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malicious Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials: A Growing Threat to Developer Security


Threat Intelligence News Platform The Hacker News has uncovered a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro that can steal crypto wallets, API keys, and credentials from unsuspecting users. According to cybersecurity researchers at Yeeth Security, the extension is equipped with heavy obfuscation techniques that enable it to bypass marketplace review, static scanning, and casual sandboxing.

  • The Hacker News has discovered a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro that delivers a browser wallet and credential stealer.
  • The extension, developed by Yeeth Security researchers, collects sensitive data such as browser profiles, crypto wallets, API keys, and SSH keys.
  • A second malicious Solidity extension, ethdevtools.solidity-language-support, was discovered impersonating a legitimate tool for Ethereum developers while containing a clipboard stealer.
  • Users who installed these extensions are advised to remove them, inspect dependency graphs, and block known command-and-control domains.
  • The malicious malware family uses heavy obfuscation techniques to evade detection and bypass marketplace review, static scanning, and casual sandboxing.



  • Threat Intelligence News Platform The Hacker News has recently uncovered a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. According to cybersecurity researchers at Yeeth Security, early iterations of the extensions – from 1.0.0 through v2.4.x – were found to beacon to Cloudflare Workers endpoints to retrieve an encrypted Python payload and execute it. However, subsequent versions starting with v3.0.0 have shifted to a full-blown information stealer that can collect browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens.

    The list of data harvested by the stealer includes GitHub ghp_ and github_pat_ tokens, GitLab glpat- tokens, AWS keys and session tokens, Cloudflare cfat_ tokens, OpenAI sk-, sk-proj-, and sk-ant- keys, Telegram bot tokens, Mnemonic and seed phrases, MetaMask, Phantom, Rabby, Coinbase, Trust, Keplr wallet vaults, Bitcoin WIF / xprv, SSH private keys (PRIVATE KEY), URL credentials, and 1Password MFA tokens.

    Cybersecurity researchers at Yeeth Security have flagged another malicious Solidity extension named ethdevtools.solidity-language-support that impersonated a Solidity language-support tool for Ethereum developers but harbored a delayed-activation clipboard stealer to scrape BIP-39 seed phrases, Ethereum private keys, and wallet addresses. The findings also coincide with the discovery of rogue VS Code extensions and npm packages that embed malicious code in dependencies or deliver a wide range of Windows-based BAT, JavaScript, and HTA droppers.

    Users who have installed these extensions are advised to remove them, inspect dependency graphs, block known command-and-control (C2) domains, and alert on use of cscript, mshta, cmd, curl, and powershell commands. The malicious malware family is equipped with heavy obfuscation techniques that enable it to bypass marketplace review, static scanning, and casual sandboxing.

    The cybersecurity company said the activity shares the same high-level playbook as WhiteCobra, another threat cluster detected in September 2025 as distributing Lumma Stealer through malicious VS Code extensions. This is not the first time threat actors have published bogus Solidity extensions across open-source ecosystems. In June 2026, Yeeth Security flagged another extension named "ascii-fetcher" that embeds malicious code in a dependency to decode an embedded command and run it via child_process.exec with windowsHide.

    In conclusion, the discovery of these malicious Solidity Pro VS Code Extensions highlights the growing threat of developer security breaches. As users increasingly rely on extensions for their development work, it is crucial for cybersecurity researchers to monitor these platforms closely and alert developers about potential threats before they become major issues.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Malicious-Solidity-Pro-VS-Code-Extensions-Steal-Crypto-Wallets-API-Keys-and-Credentials-A-Growing-Threat-to-Developer-Security-ehn.shtml

  • https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html


  • Published: Mon Aug 10 04:09:30 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us