Solidity Pro VSCode extension found compromised with data theft, remote execution

SlowMist warned that historical versions of the Solidity Pro Visual Studio Code extension contained credential-harvesting, remote execution and remote update capabilities. The affected Extension IDs were helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, both of which Open VSX added to its malicious extension control list on August 6–7, 2026. The firm found delayed payload execution and CI-environment checks in version 2.4.1, while version 3.4.0 collected private keys, wallet data, cloud credentials, tokens and API keys before exfiltrating them to obfuscated Cloudflare Workers endpoints. An AutoUpdater also installed remote VSIX packages without integrity checks. SlowMist said later releases appeared clean because malicious modules were excluded from the package, although they remained in the GitHub source tree. Users are advised to remove related installations, rotate potentially exposed credentials and wallets, and audit their systems.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.