By Interestana AI Editorial — AI-drafted, human-overseen. How we report
VS Code Extensions Steal Crypto Wallets and API Keys

Cybersecurity researchers have identified malicious extensions within the Microsoft Visual Studio Code (VS Code) marketplace that are designed to steal sensitive user information, including cryptocurrency wallets, API keys, and credentials. One such extension, named Solidity Pro with the identifier "solidity-pro", was found to be delivering a browser wallet and credential stealer. The researchers noted that two specific extensions, "helper-beeps.solidity-pro" and "web3devtoolsx.solidity-pro", were part of this malicious campaign. Although these specific extensions are no longer available on the Open VSX registry, the underlying threat and the methods employed highlight ongoing risks associated with software development tools and their associated marketplaces. The attackers leverage the trust developers place in these extensions to distribute malware. The Solidity Pro extension, in particular, appears to be engineered to target developers working with blockchain technologies, given its name and the nature of the stolen data. Cryptocurrency wallets and API keys are high-value targets for cybercriminals, as they can grant direct access to digital assets and sensitive backend services. The theft of API keys can lead to unauthorized access to cloud services, data breaches, and further exploitation of compromised systems. The researchers' findings underscore the importance of rigorous security vetting for all extensions and plugins used in development environments. The fact that these extensions were able to infiltrate the marketplace suggests potential gaps in the security review processes of these platforms. Developers are advised to exercise extreme caution when installing any third-party extensions, even those that appear to be legitimate or are from seemingly reputable sources. Verifying the developer's reputation, checking user reviews for any signs of suspicious activity, and limiting the permissions granted to extensions are crucial steps in mitigating these risks. The discovery of these malicious extensions serves as a stark reminder of the evolving tactics employed by cybercriminals to compromise software supply chains and target developers. The ongoing threat necessitates continuous vigilance and proactive security measures from both platform providers and individual users to safeguard sensitive information and digital assets. The researchers have not yet disclosed the full extent of the compromise or the number of users potentially affected, but the nature of the stolen data suggests a significant risk to individuals and organizations utilizing these compromised tools. Further investigation into the distribution network and the full capabilities of the malware is likely underway by cybersecurity firms and potentially law enforcement agencies. The incident also prompts a broader discussion about the security of open-source software development tools and the need for enhanced security protocols across all digital marketplaces.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.