Malicious VS Code Extensions Masquerading as Solidity Tools Steal Crypto Wallets, API Keys and Credentials
Two malicious extensions for Visual Studio Code promoted as utilities for Solidity development have been used to steal cryptocurrency wallet data from browsers along with API keys and stored credentials. The incident once again highlights supply-chain risks in extension marketplaces: a single installation is enough to expose development secrets.
The security community has identified two malicious extensions that present themselves as tools for Solidity and the Web3 ecosystem but actually aim to harvest sensitive information from developer machines. The operation uses the clear lure of the name Solidity Pro and targets developers working with smart contracts who typically keep credentials, tokens and active sessions in the same environment.
The objective extends beyond the editor itself. Detected activity includes collection of data associated with browser-based crypto wallets, saved credentials and common development secrets such as API keys and other tokens. This type of theft is especially dangerous because one compromised workstation can open doors to lateral movement from repositories to cloud services and, in the case of wallets, direct loss of funds.
Indicators that have emerged point to two specific identifiers in the extension store: helper-beeps.solidity-pro and web3devtoolsx.solidity-pro. In a supply-chain attack of this kind the vector is rarely a complex exploit but rather an apparently legitimate installation that exploits trust in the extension ecosystem.
The operational risk grows because the editor coexists with .env files, SSH keys, system credential managers and active sessions in critical services. If an extension manages to read or exfiltrate that data, recovery is not limited to uninstalling it: organizations must assume every accessible secret on the machine may have been exposed.
The immediate recommendation is to uninstall helper-beeps.solidity-pro and web3devtoolsx.solidity-pro and prevent reinstallation. All secrets on the affected machine should be treated as compromised, tokens and API keys rotated, and recent credential usage reviewed for anomalous activity. To reduce the attack surface, teams should audit their VS Code extension inventory, remove non-essential extensions and enforce stricter installation policies with allow-lists and centralized logging.
In Web3 environments it is also advisable to separate sensitive operations from the development workstation through dedicated browser profiles, isolated accounts and, where possible, hardware wallets for signing transactions outside the reach of local software.
Related articles
Security Researcher Builds SAST Scanner for AI-Generated Code and Audits 3,800 Public Repositories
A developer released AigisSAST, a lightweight open-source static analysis tool written in pure Python with no external dependencies, specifically tuned to detect common mistakes made by AI coding assistants. The scanner was run across roughly 3,800 repositories ranging from small pet projects to popular open-source platforms. It identified thousands of potential secrets and misconfigurations, yet manual review reduced the number of genuine leaks to approximately 30 cases, mostly Telegram bot tokens, database credentials, and committed .env files. The project also examined 471 production-grade Telegram bots handling payments and VPN services, uncovering 31 repositories that exposed real credentials either in current code or in Git history. AigisSAST includes 21 detection rules, 193 regression tests, automatic remediation via the fix command, and seamless integration with GitHub Actions. The author deliberately avoided validating any discovered keys to stay within ethical research boundaries.
Vendor Responsibility in Open Source: Licensing Obligations Exposed by Sonatype Nexus Changes
The article examines how vendors building products on copyleft open source projects like Nexus Repository OSS inherit significant legal and security responsibilities under licenses such as EPL 1.0. Sonatype's February 2025 shift from regular OSS binary releases to a limited Community Edition forces downstream vendors to handle their own builds, patch porting, and compliance disclosures. This change highlights the second part of copyleft licenses that outlines obligations for distributors, including revealing modifications and assuming liability for the final product. Security implications arise because critical vulnerabilities in the upstream project must now be tracked and patched by the vendor, with delays creating measurable supply chain risks. The piece provides a practical checklist for buyers to assess licensing hygiene, SBOM availability, and vulnerability response times in any open source-based solution.
PhantomSub Campaign Deploys 101 Malicious npm Packages to Hijack WhatsApp Accounts for Unauthorized Channel Subscriptions
Researchers at OX Security uncovered 101 malicious npm packages tied to the PhantomSub campaign that abuse connected WhatsApp accounts to subscribe users to promotional channels without consent. The packages disguise themselves as modified versions of the open-source Baileys library used for WhatsApp automation. Attackers rely on authenticated sessions rather than simple package installation, allowing them to control subscriptions through lists stored on GitHub, in plaintext, or as encoded identifiers. The packages have accumulated roughly 490,000 downloads, including 116,000 in the past 30 days, though the exact number of compromised accounts remains unknown. As of 28 September, npm had removed only 16 of the identified packages. The operation ultimately benefits channels selling bots, game resources, accounts, and promotion services by inflating subscriber counts while disabling notifications to hide the activity.
AI Model Hallucinations Fuel Slopsquatting Attacks on PyPI and npm Registries
Researchers identified 139 package names consistently hallucinated by five different AI models across Python and JavaScript ecosystems. Seven of these names are already registered on PyPI and npm, including one previously used to distribute malware. The attack vector, termed slopsquatting, allows attackers to register AI-suggested package names and execute code with developer privileges during installation. One package, metro-evaluator, contained malicious code removed by npm in December 2025, while another empty package css-color-stop began receiving downloads after the list was published. Real projects such as odf and lusid now occupy names that AI models recommend, causing developers to install unrelated software. Studies show hallucination rates between 4.62% and 21.7% depending on the model, with commercial models performing better than open-source ones. The findings highlight risks when AI coding agents execute dependency installation commands without human verification.