WhiteCobra is a financially motivated threat actor focused on developer ecosystems, particularly Visual Studio Code and compatible editor marketplaces such as OpenVSX, Cursor, and Windsurf. The actor is known for planting malicious extensions that impersonate legitimate development tools, especially Solidity and Web3-related utilities, in order to steal cryptocurrency wallet material and other sensitive developer secrets. WhiteCobra has been linked to at least 24 malicious extensions and to campaigns distributing both crypto-stealing malware and broader information stealers. Reported functionality includes theft of browser-stored data, cryptocurrency wallet vaults and seed phrases, source-control tokens, cloud credentials, API keys, SSH keys, and Telegram bot tokens, followed by exfiltration of stolen data. Related activity has also included clipboard-stealing and wallet-address replacement behavior targeting cryptocurrency transactions, as well as prior distribution of Lumma Stealer through malicious VS Code extensions. The actor’s tradecraft emphasizes supply-chain style abuse of trusted developer marketplaces and evasion of marketplace review. Observed techniques include heavy code obfuscation, delayed activation, use of intermediate clean releases, runtime string reconstruction, and staged payload delivery. WhiteCobra’s targeting strongly centers on cryptocurrency users and developers, particularly Ethereum and Solidity developers whose workstations may contain wallet secrets, private keys, and access tokens valuable for follow-on theft. WhiteCobra is associated with malicious extensions that affected users of Visual Studio Code and related forks, and reporting has tied the actor to extensions with basic ransomware capabilities in addition to crypto theft. The available evidence most strongly supports classification as a developer-focused, crypto-theft-oriented intrusion set rather than a nation-state espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat cluster previously detected distributing Lumma Stealer through malicious VS Code extensions; referenced here as having a similar playbook to the current activity.
Abused the VS Code marketplace by publishing numerous crypto-stealing extensions; associated in the content with a malicious extension that also had basic ransomware capabilities.
Associated with flooding the VS Code Marketplace with crypto-stealing malicious extensions.
WhiteCobra is responsible for distributing malicious extensions in the VSCode and Cursor code editor marketplaces, specifically targeting cryptocurrency users to steal wallet credentials and assets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.