Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious VS Code Extensions Target Crypto Wallets

Malicious VS Code Extensions Target Crypto Wallets

Posted on August 10, 2026 By CWS

Cybersecurity experts have raised alarms about two malicious extensions for Microsoft Visual Studio Code (VS Code), known as Solidity Pro. These extensions, identified as ‘helper-beeps.solidity-pro’ and ‘web3devtoolsx.solidity-pro’, have been implicated in the theft of browser wallets and credentials.

Initial Detection and Methodology

The extensions, though no longer available on the Open VSX marketplace, still have a GitHub repository for ‘web3devtoolsx.solidity-pro’. Research by Yeeth Security revealed that earlier versions of these extensions communicated with Cloudflare Workers endpoints to download and execute an encrypted Python payload.

With the release of version 3.0.0, the extensions evolved into comprehensive information stealers. These malicious tools are now capable of collecting sensitive data such as browser profiles, crypto wallets, source-control tokens, and API keys. The stolen information is then transmitted through a Telegram bot channel.

Data Targeted by the Malware

The array of data targeted by these extensions includes GitHub and GitLab tokens, AWS keys, Cloudflare tokens, and various keys for OpenAI. Additionally, the malware captures mnemonic and seed phrases for multiple crypto wallets including MetaMask, Phantom, and Coinbase. It also targets private keys and credentials stored in URLs, posing a significant threat to user security.

These extensions utilize sophisticated obfuscation techniques to bypass security reviews and scans, which includes deploying intermediate clean versions and implementing delayed activation of malicious code. This allows the malware to remain undetected during initial scans and activate only after a certain period.

Comparative Threat Analysis

The tactics employed by these extensions are reminiscent of those used by WhiteCobra, a threat actor identified in 2025 for distributing the Lumma Stealer via malicious VS Code extensions. This pattern of deploying harmful extensions highlights the ongoing risk posed by such threats in open-source ecosystems.

In a similar vein, another extension flagged this year, ‘ethdevtools.solidity-language-support’, masqueraded as a legitimate tool for Ethereum developers while secretly harboring a clipboard stealer. This malware replaced copied crypto addresses with those controlled by attackers, thereby facilitating unauthorized transactions.

Recommended User Actions

Users who have installed these dangerous extensions are strongly advised to uninstall them immediately. Additional protective measures include reviewing dependency graphs, blocking known command-and-control domains, and monitoring for suspicious activity involving tools like cscript, mshta, cmd, curl, and powershell.

As the cybersecurity landscape evolves, staying vigilant and informed about emerging threats is crucial for safeguarding sensitive data and maintaining secure digital environments.

The Hacker News Tags:browser wallets, credential stealing, crypto theft, Cybersecurity, GitHub, Malware, Solidity Pro, threat detection, VS Code, Yeeth Security

Post navigation

Previous Post: OpenAI Halts AI Model Astra Over Cybersecurity Concerns
Next Post: WordPress Plugins Vulnerable in New Supply Chain Attack

Related Posts

Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw Chrome Targeted by Active In-the-Wild Exploit Tied to Undisclosed High-Severity Flaw The Hacker News
Security Flaws in AirDrop and Quick Share Exposed Security Flaws in AirDrop and Quick Share Exposed The Hacker News
Mastra npm Packages Compromised in Supply Chain Attack Mastra npm Packages Compromised in Supply Chain Attack The Hacker News
CanisterWorm Exploits Trivy Attack, Targets npm Packages CanisterWorm Exploits Trivy Attack, Targets npm Packages The Hacker News
WhatsApp Warns 200 Users of Fake iOS App Spyware WhatsApp Warns 200 Users of Fake iOS App Spyware The Hacker News
AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics
  • Hackers Exploit Private APN to Target Polish Energy Facility
  • Claude Opus 5 Reduces Prompt Injection Attacks to 2%
  • Levi Strauss Reports Data Breach from Cyberattack
  • WordPress Plugins Vulnerable in New Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics
  • Hackers Exploit Private APN to Target Polish Energy Facility
  • Claude Opus 5 Reduces Prompt Injection Attacks to 2%
  • Levi Strauss Reports Data Breach from Cyberattack
  • WordPress Plugins Vulnerable in New Supply Chain Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark