Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials - The Hacker News
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer.
Although neither of the extensions is now available on Open VSX, the GitHub repository for "web3devtoolsx/solidity-pro" continues to remain accessible as of writing.
According to Yeeth Security, early iterations of the extensions – from 1.0.0 through v2.4.x – were found to beacon to Cloudflare Workers endpoints to retrieve an encrypted Python payload and execute it.
Subsequent versions starting with v3.0.0, on the other hand, have shifted to a full-blown information stealer that can collect browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. The captured data is then exfiltrated via a Telegram bot upload.
Source: The Hacker News