Cybersecurity researchers have identified malicious Microsoft Visual Studio Code extensions operating under the name Solidity Pro that are designed to steal cryptocurrency wallets, developer credentials, API keys, and other sensitive information from compromised systems. The affected extensions, helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, were previously available through Open VSX but have since been removed. However, researchers noted that the GitHub repository for web3devtoolsx/solidity-pro remained accessible at the time of their analysis. According to Yeeth Security, the malicious extensions evolved significantly over multiple releases, transforming from a relatively simple downloader into a sophisticated information stealing platform capable of targeting developers, cryptocurrency users, and enterprise credentials. The discovery highlights the growing abuse of development tools and open source ecosystems by threat actors seeking access to valuable authentication tokens, cryptocurrency assets, and sensitive enterprise information.
According to Yeeth Security, versions 1.0.0 through 2.4.x of the extensions contacted Cloudflare Workers infrastructure to retrieve an encrypted Python payload for execution after installation. Beginning with version 3.0.0, the extensions introduced a more advanced information stealer capable of collecting browser profiles, cryptocurrency wallet data, source control authentication tokens, API keys, Secure Shell keys, Telegram bot tokens, and other credentials before transmitting the stolen information through a Telegram bot. Researchers found that the malware specifically targets GitHub authentication tokens, GitLab personal access tokens, Amazon Web Services credentials, Cloudflare authentication tokens, OpenAI API keys, Telegram bot credentials, mnemonic and seed phrases, cryptocurrency wallet vaults including MetaMask, Phantom, Rabby, Coinbase Wallet, Trust Wallet, and Keplr, Bitcoin private keys, Secure Shell private keys, URL based credentials, and one time authentication tokens associated with 1Password. The malware also employs extensive code obfuscation, intermediate clean releases, and delayed activation mechanisms that postpone malicious activity for several hours or even days after installation, allowing the extensions to evade marketplace reviews, automated security scanning, and sandbox analysis.
Researchers explained that the delayed activation strategy helps build user trust before malicious functionality is enabled. By the time the harmful code begins executing, users often consider the extension legitimate while automated scanning systems have already completed their analysis. Yeeth Security stated that the malware continuously changes implementation techniques by splitting strings across runtime tables, reconstructing them dynamically, and modifying method names between releases to complicate signature based detection. The cybersecurity company also noted similarities between the campaign and the previously identified WhiteCobra threat cluster, which was linked to malicious Visual Studio Code extensions distributing Lumma Stealer during 2025. The researchers further observed that attackers have repeatedly targeted developers through fraudulent Solidity related extensions. In June 2026, Yeeth Security reported another malicious extension named ethdevtools.solidity-language-support, which impersonated a legitimate Solidity language support extension while secretly deploying a delayed activation clipboard stealer capable of replacing copied cryptocurrency wallet addresses with attacker controlled addresses using the trusted vscode.env.clipboard.writeText application programming interface. Because the technique relies on legitimate Visual Studio Code functionality rather than suspicious system calls, it can evade many traditional security detection methods.
The latest findings also coincide with several additional malicious software supply chain campaigns targeting developers. Researchers identified a malicious npm package named ascii-fetcher containing a dependency called @jaymara/jsononifier, which decodes embedded commands and executes them through the Node.js child process functionality. They also discovered ten additional Visual Studio Code extensions distributing Windows based batch, JavaScript, and Hypertext Application droppers, while another extension identified as DigitalBarberTrim.html-entity-codec selectively installed remote Visual Studio Code extension packages after identifying supported development environments including Cursor, Windsurf, Codium, and Positron. Yeeth Security advised organizations and developers who previously installed the affected Solidity Pro extensions to remove them immediately, review software dependency graphs, block known command and control infrastructure, and monitor systems for suspicious execution of cscript, mshta, cmd, curl, and PowerShell commands. The findings reinforce the importance of carefully verifying development tools, monitoring software supply chains, and implementing stronger security controls to protect developer environments from increasingly sophisticated malware campaigns targeting software engineers and cryptocurrency users.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





