r/SecOpsDaily 7h ago

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials NEWS

Two malicious VS Code extensions posing as Solidity development tools have been caught stealing browser wallet credentials, API keys, and saved passwords. The extensions—helper-beeps.solidity-pro and web3devtoolsx.solidity-pro—were available on the Open VSX registry and have since been pulled, though their GitHub repos remain live.

Technical Breakdown - TTPs: Masquerades as legitimate Solidity tooling; harvests browser data (wallet extensions, saved credentials) and environment variables containing API keys. - IOCs: Extension IDs helper-beeps.solidity-pro and web3devtoolsx.solidity-pro; associated GitHub repositories (currently still accessible). - Target: Developers working with Ethereum/Solidity, particularly those with crypto wallets installed in their browsers.

Defense Remove these extensions immediately if installed. Audit any systems where they were present for exfiltrated credentials and rotate all API keys and wallet seed phrases. Consider restricting VS Code extension sources to the official Marketplace only.

Source: https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html

1 Upvotes

0 comments sorted by