Cybersecurity researchers have issued a stark warning to blockchain developers after discovering a series of malicious Visual Studio Code extensions designed to drain cryptocurrency wallets and steal sensitive credentials. The tools, operating under names like Solidity Pro, specifically targeted the Web3 community by masquerading as helpful development utilities. While some versions of these extensions have already been scrubbed from official marketplaces, security experts warn that remnants still exist in public repositories, posing a lingering threat to unsuspecting coders.
The sophistication of the attack evolved over time, beginning with simple payloads before transforming into a comprehensive information stealer. According to findings from Yeeth Security, later versions of the software were capable of harvesting everything from MetaMask and Coinbase wallet vaults to AWS keys and OpenAI API tokens. Even highly secure assets like SSH private keys and 1Password MFA tokens were within the attackers’ reach. Once this wealth of data was collected, it was quietly exfiltrated using a Telegram bot, leaving the victim unaware that their digital identity had been compromised.
To avoid detection, the hackers employed a deceptive strategy involving delayed activation and heavy obfuscation. By ensuring the malicious code remained dormant for several hours or even days after installation, the attackers bypassed automated sandbox scanners that typically monitor a package for only a few minutes. This window allowed users to grow comfortable with the extension before it suddenly activated its theft mechanisms. Researchers noted that this tactic mirrors those used by previous threat clusters like WhiteCobra, suggesting a coordinated effort to exploit the trust inherent in open-source developer ecosystems.
This incident is part of a broader trend where bad actors impersonate essential coding tools to gain deep access to developer machines. Recent reports highlight similar schemes involving fake language support tools and corrupted npm packages that could execute remote commands on a user’s system. Experts are urging any developers who may have installed these problematic extensions to remove them immediately and conduct thorough audits of their dependency graphs and system logs for unauthorized activity.

