{"id":2298,"date":"2026-08-10T08:33:17","date_gmt":"2026-08-10T08:33:17","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2298"},"modified":"2026-08-10T08:33:17","modified_gmt":"2026-08-10T08:33:17","slug":"solidity-pro-vs-code-extensions-steal-crypto-wallets-api-keys-and-credentials","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2298","title":{"rendered":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 10, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cybercrime  <\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjR5_Dx4heVYIxaujo8ybl0OFdVuLzMFe0qdEdr6-q_QTdhSVlgHdrP6MeooXamFpRNfHjoAqTquvk3CkkCKUw1TQDkQJCrZY1RTC9iYK_bsTLNvpj0BZfFKFcnlt1RAlBvfcsWeSuLAn6Gwh9lur7v9-HlH-6ZpSmw7npsn9TSZAEpwFSFE54_xcFPcuDi\/s1700-e365\/pro.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (\u00absolidity-pro\u00bb) that has been observed delivering a browser wallet and credential stealer.<\/p>\n<p>The names of the extensions are below &#8211;<\/p>\n<ul>\n<li>helper-beeps.solidity-pro<\/li>\n<li>web3devtoolsx.solidity-pro<\/li>\n<\/ul>\n<p>Although neither of the extensions is now available on Open VSX, the GitHub repository for \u00ab<a href=\"https:\/\/github.com\/web3devtoolsx\/solidity-pro\" target=\"_blank\">web3devtoolsx\/solidity-pro<\/a>\u00bb continues to remain accessible as of writing.<\/p>\n<p>According to <a href=\"https:\/\/yeethsecurity.com\/blog\/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram\" target=\"_blank\">Yeeth Security<\/a>, early iterations of the extensions \u2013 from 1.0.0 through v2.4.x \u2013 were found to beacon to Cloudflare Workers endpoints to retrieve an encrypted Python payload and execute it.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Subsequent versions starting with v3.0.0, on the other hand, have shifted to a full-blown information stealer that can collect browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. The captured data is then exfiltrated via a Telegram bot upload.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The list of data harvested by the stealer is as follows &#8211;<\/p>\n<ul>\n<li>GitHub ghp_ and github_pat_ tokens<\/li>\n<li>GitLab glpat- tokens<\/li>\n<li>AWS keys and session tokens<\/li>\n<li>Cloudflare cfat_ tokens<\/li>\n<li>OpenAI sk-, sk-proj-, and sk-ant- keys<\/li>\n<li>Telegram bot tokens<\/li>\n<li>Mnemonic and seed phrases<\/li>\n<li>MetaMask, Phantom, Rabby, Coinbase, Trust, Keplr wallet vaults<\/li>\n<li>Bitcoin WIF \/ xprv<\/li>\n<li>SSH private keys (PRIVATE KEY)<\/li>\n<li>URL credentials and 1Password MFA tokens<\/li>\n<\/ul>\n<p>The malware family is also equipped to bypass marketplace review, static scanning, and casual sandboxing through heavy obfuscation, intermediate clean versions to build trust, and randomized delayed activation that causes the malicious code to run several hours or days after installation.<\/p>\n<p>\u00abBy the time the malicious branch runs, the user has already decided the extension is useful, and automated scanners that only observe the package for minutes have moved on,\u00bb Yeeth Security said. \u00abThe obfuscation is not decorative; it splits strings across IIFE tables, reassembles them at runtime, and switches method names between releases so signature-based detection must track a moving target.\u00bb<\/p>\n<p>The cybersecurity company said the activity shares the same high-level playbook as <a href=\"https:\/\/yeethsecurity.com\/blog\/2025-09-03-WhiteCobra\" target=\"_blank\">WhiteCobra<\/a>, another threat cluster that was detected in September 2025 as distributing Lumma Stealer through malicious VS Code extensions.<\/p>\n<p>This is not the first time threat actors have published bogus Solidity extensions across open-source ecosystems. In June 2026, Yeeth Security flagged another extension named \u00ab<a href=\"https:\/\/yeethsecurity.com\/blog\/2026-06-21-ethdevtools-Clipboard-Crypto-Stealer\" target=\"_blank\">ethdevtools.solidity-language-support<\/a>\u00bb that impersonated a  Solidity language-support tool for Ethereum developers, but harbored a delayed-activation clipboard stealer to scrape BIP-39 seed phrases, Ethereum private keys, and wallet addresses.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abWhen a recognized crypto address is on the clipboard, it replaces the pasted value with an attacker-controlled address,\u00bb it added. \u00abThe swap happens through vscode.env.clipboard.writeText, a first-party API call that requires no child_process, no network access, and no file writes. Static scanners that only look for dangerous Node imports will not see it.\u00bb<\/p>\n<p>The findings also coincide with the discovery of a number of rogue VS Code extensions and npm packages &#8211;<\/p>\n<ul>\n<li>An npm package called \u00ab<a href=\"https:\/\/yeethsecurity.com\/blog\/2026-07-02-The-jsononifier-npm-Dropper\" target=\"_blank\">ascii-fetcher<\/a>,\u00bb which embeds the malicious code in a dependency named \u00ab@jaymara\/jsononifier\u00bb to decode an embedded command (in the observed case, \u00abcalc.exe\u00bb) and run it via \u00abchild_process.exec\u00bb with \u00abwindowsHide\u00bb<\/li>\n<li><a href=\"https:\/\/yeethsecurity.com\/blog\/2026-07-02-The-Windows-Installer-Dropper-Family\" target=\"_blank\">A set of 10 VS Code extensions<\/a> that deliver a wide range of Windows-based BAT, JavaScript, and HTA droppers, with two of them bundling an npm dependency that uses a postinstall hook to fetch and execute a remote payload<\/li>\n<li>A VS Code extension named \u00ab<a href=\"https:\/\/yeethsecurity.com\/blog\/2026-07-02-DigitalBarberTrim-Multi-IDE-VSIX-Installer\" target=\"_blank\">DigitalBarberTrim.html-entity-codec<\/a>\u00bb that drops a remote VSIX file in select versions after enumerating known VS Code forks like Cursor, Windsurf, Codium, and Positron, while serving a \u00abnearly empty stub\u00bb in others to fly under the radar.<\/li>\n<\/ul>\n<p>Users who have installed the extensions are advised to remove them, inspect dependency graphs, block known command-and-control (C2) domains, and alert on use of cscript, mshta, cmd, curl, and powershell commands.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 10, 2026Malware \/ Cybercrime Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (\u00absolidity-pro\u00bb) that has been observed delivering a browser&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2299,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[14,10,446,143,361,144,1156,2971,571,617],"class_list":["post-2298","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-api","tag-code","tag-credentials","tag-crypto","tag-extensions","tag-keys","tag-pro","tag-solidity","tag-steal","tag-wallets"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2298","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2298"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2298\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2299"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2298"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2298"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}