Malicious Solidity Pro VS Code Extension Compromises Crypto Wallets and Credentials

Malicious Solidity Pro VS Code Extension Compromises Crypto Wallets and Credentials

First seen 10 Aug 2026, 13:32 UTC Feeds.4SysopsGbhackersCybersecuritynews 79% similarity 66.0

Article Content

Browse articles
ThreatCluster

A malicious VS Code extension named Solidity Pro has been discovered stealing sensitive data from developers, including cryptocurrency wallets, API keys, and SSH keys. The extension utilized delayed activation and obfuscation techniques to evade detection before executing its theft. Affected users are primarily developers working with Solidity, a programming language for Ethereum smart contracts. Although the malicious extensions have been removed from Open VSX, a related GitHub repository remains accessible, posing ongoing risks. This incident highlights the vulnerabilities in trusted development environments and the potential for significant data loss. Developers are advised to remain vigilant and review their installed extensions for any suspicious activity.

Key Points: • Malicious Solidity Pro extension targets developers, stealing crypto wallets and credentials. • The extension employed delayed activation to avoid detection during initial reviews. • Related GitHub repository remains accessible, continuing the risk for developers.

ThreatCluster AI How this analysis works

Timeline

2026-08-10
Malicious extension discovered
The Solidity Pro VS Code extension was found to be stealing sensitive data from developers.
Cybersecuritynews
2026-08-10
Extension removed from Open VSX
The malicious extensions were taken down from the Open VSX marketplace following the discovery.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story