Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Summary

Cybersecurity researchers have identified a malicious Visual Studio Code extension called Solidity Pro that steals cryptocurrency wallets, API keys, and user credentials. The extension, which has since been removed from Open VSX, aimed to compromise sensitive information from developers using the IDE.

IFF Assessment

FOE

This malicious extension poses a direct threat to developers by stealing sensitive information, making it bad news for defenders.

Defender Context

This incident highlights the ongoing risk of supply chain attacks targeting developer tools like VS Code extensions. Defenders should be vigilant about the extensions they install and encourage developers to implement strict vetting processes for all third-party software integrated into their development environments.

Read Full Story →