Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious VS Code Extensions Target Crypto Wallets

Malicious VS Code Extensions Target Crypto Wallets

Posted on August 10, 2026 By CWS

Cybersecurity experts have raised alarms about two malicious extensions for Microsoft Visual Studio Code (VS Code), known as Solidity Pro. These extensions, identified as ‘helper-beeps.solidity-pro’ and ‘web3devtoolsx.solidity-pro’, have been implicated in the theft of browser wallets and credentials.

Initial Detection and Methodology

The extensions, though no longer available on the Open VSX marketplace, still have a GitHub repository for ‘web3devtoolsx.solidity-pro’. Research by Yeeth Security revealed that earlier versions of these extensions communicated with Cloudflare Workers endpoints to download and execute an encrypted Python payload.

With the release of version 3.0.0, the extensions evolved into comprehensive information stealers. These malicious tools are now capable of collecting sensitive data such as browser profiles, crypto wallets, source-control tokens, and API keys. The stolen information is then transmitted through a Telegram bot channel.

Data Targeted by the Malware

The array of data targeted by these extensions includes GitHub and GitLab tokens, AWS keys, Cloudflare tokens, and various keys for OpenAI. Additionally, the malware captures mnemonic and seed phrases for multiple crypto wallets including MetaMask, Phantom, and Coinbase. It also targets private keys and credentials stored in URLs, posing a significant threat to user security.

These extensions utilize sophisticated obfuscation techniques to bypass security reviews and scans, which includes deploying intermediate clean versions and implementing delayed activation of malicious code. This allows the malware to remain undetected during initial scans and activate only after a certain period.

Comparative Threat Analysis

The tactics employed by these extensions are reminiscent of those used by WhiteCobra, a threat actor identified in 2025 for distributing the Lumma Stealer via malicious VS Code extensions. This pattern of deploying harmful extensions highlights the ongoing risk posed by such threats in open-source ecosystems.

In a similar vein, another extension flagged this year, ‘ethdevtools.solidity-language-support’, masqueraded as a legitimate tool for Ethereum developers while secretly harboring a clipboard stealer. This malware replaced copied crypto addresses with those controlled by attackers, thereby facilitating unauthorized transactions.

Recommended User Actions

Users who have installed these dangerous extensions are strongly advised to uninstall them immediately. Additional protective measures include reviewing dependency graphs, blocking known command-and-control domains, and monitoring for suspicious activity involving tools like cscript, mshta, cmd, curl, and powershell.

As the cybersecurity landscape evolves, staying vigilant and informed about emerging threats is crucial for safeguarding sensitive data and maintaining secure digital environments.

The Hacker News Tags:browser wallets, credential stealing, crypto theft, Cybersecurity, GitHub, Malware, Solidity Pro, threat detection, VS Code, Yeeth Security

Post navigation

Previous Post: OpenAI Halts AI Model Astra Over Cybersecurity Concerns
Next Post: WordPress Plugins Vulnerable in New Supply Chain Attack

Related Posts

Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger The Hacker News
ChocoPoC Malware Targets Researchers with Fake Exploits ChocoPoC Malware Targets Researchers with Fake Exploits The Hacker News
MemGhost Attack Alters AI Memory with a Single Email MemGhost Attack Alters AI Memory with a Single Email The Hacker News
Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws The Hacker News
Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets Five New Exploited Bugs Land in CISA’s Catalog — Oracle and Microsoft Among Targets The Hacker News
Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaws in Connective eID Extension Resolved
  • Critical SQL Flaw Patched by Metabase Amid Zero-Day Exploit
  • Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics
  • Hackers Exploit Private APN to Target Polish Energy Facility
  • Claude Opus 5 Reduces Prompt Injection Attacks to 2%

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaws in Connective eID Extension Resolved
  • Critical SQL Flaw Patched by Metabase Amid Zero-Day Exploit
  • Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics
  • Hackers Exploit Private APN to Target Polish Energy Facility
  • Claude Opus 5 Reduces Prompt Injection Attacks to 2%

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark