Malicious VS Code Extensions Masquerading as Solidity Tools Steal Crypto Wallets, API Keys and Credentials
Two malicious extensions for Visual Studio Code promoted as utilities for Solidity development have been used to steal cryptocurrency wallet data from browsers along with API keys and stored credentials. The incident once again highlights supply-chain risks in extension marketplaces: a single installation is enough to expose development secrets.
The security community has identified two malicious extensions that present themselves as tools for Solidity and the Web3 ecosystem but actually aim to harvest sensitive information from developer machines. The operation uses the clear lure of the name Solidity Pro and targets developers working with smart contracts who typically keep credentials, tokens and active sessions in the same environment.
The objective extends beyond the editor itself. Detected activity includes collection of data associated with browser-based crypto wallets, saved credentials and common development secrets such as API keys and other tokens. This type of theft is especially dangerous because one compromised workstation can open doors to lateral movement from repositories to cloud services and, in the case of wallets, direct loss of funds.
Indicators that have emerged point to two specific identifiers in the extension store: helper-beeps.solidity-pro and web3devtoolsx.solidity-pro. In a supply-chain attack of this kind the vector is rarely a complex exploit but rather an apparently legitimate installation that exploits trust in the extension ecosystem.
The operational risk grows because the editor coexists with .env files, SSH keys, system credential managers and active sessions in critical services. If an extension manages to read or exfiltrate that data, recovery is not limited to uninstalling it: organizations must assume every accessible secret on the machine may have been exposed.
The immediate recommendation is to uninstall helper-beeps.solidity-pro and web3devtoolsx.solidity-pro and prevent reinstallation. All secrets on the affected machine should be treated as compromised, tokens and API keys rotated, and recent credential usage reviewed for anomalous activity. To reduce the attack surface, teams should audit their VS Code extension inventory, remove non-essential extensions and enforce stricter installation policies with allow-lists and centralized logging.
In Web3 environments it is also advisable to separate sensitive operations from the development workstation through dedicated browser profiles, isolated accounts and, where possible, hardware wallets for signing transactions outside the reach of local software.
Related articles
Supply Chain Attack Targets Arch Linux Community Repository
Arch Linux has temporarily suspended package adoptions in the Arch User Repository after detecting accounts taking over abandoned projects to insert malicious code. The platform later expanded the restriction by blocking all new submissions to the AUR to contain ongoing supply chain attacks. Attackers were adopting packages without active maintainers and introducing harmful changes through subsequent commits that could bypass user scrutiny due to established project history. Newly created packages containing malicious build commands, including requests for elevated privileges, were also discovered. Affected accounts have been banned and identified projects removed from the repository. The incident does not impact official Arch Linux repositories, with risk limited to community-maintained AUR packages that require manual review of PKGBUILD files before installation or updates.
Malicious npm Packages Deploy Multi-Stage Trojan with Embedded GitLab Keys
Positive Technologies researchers uncovered a campaign in which an attacker published multiple trojanized packages to the npm registry under the accounts alex05255, mdrafiqulislamrabby, b.w1001, abdev8773 and mollspotwood54400. The affected packages include svg-fetcher, tradepilot, polytrade, polymarket-kit, react-svg-chunk, gamified-trading-system, font-huge, font-hub, mdb-vite, router-processor and route-processor. Each package concatenates several constants to build a C2 URL, downloads the next stage identified as token versions 106, 107, 108 and 116, and sends the hardcoded value logo in the bearrtoken header. Later stages contain heavily obfuscated JavaScript that collects username, hostname and operating-system information before establishing a WebSocket channel for command execution. Releases 106 and 116 also embed a public-private key pair belonging to a private GitLab instance operated by the threat actor, suggesting the use of CI/CD pipelines for code obfuscation and stage generation. The findings highlight the continued risk of supply-chain attacks through popular open-source repositories and the value of automated package monitoring.
How to Audit All Python Virtual Environments for Compromised Packages Without Executing Python
The article describes a practical workflow for discovering whether any Python virtual environments contain known malicious package versions. The author maintains a registry of all .venv directories across local disks and external volumes using find commands and shell hooks. A Bash script then iterates through the registry and runs uv pip freeze against each environment to list installed dependencies without invoking the Python interpreter. This approach avoids risks highlighted by recent supply-chain attacks on packages such as LiteLLM, where even python -V or pip freeze could trigger malicious .pth files. The method also supports locating outdated packages, identifying usage of deprecated libraries, and searching project code for specific functions. Configuration settings like PIP_REQUIRE_VIRTUALENV=true and the uv tool further prevent accidental global installations.
GitHub and PyPI Introduce Time-Based Defenses Against Supply Chain Attacks
GitHub and PyPI have activated new time-based barriers to slow down supply chain attacks. Dependabot now waits a default of 72 hours before proposing version updates, while PyPI rejects new files added to releases older than 14 days. The changes target non-security version updates and attempts to poison older stable releases. Security updates remain immediate, and the cooldown can be adjusted via dependabot.yml. The PyPI restriction, effective since July 8 2026, addresses risks from compromised tokens or CI/CD pipelines. Both platforms aim to give the community time to detect malicious packages before widespread adoption.