WhiteCobra is a threat actor associated with a campaign targeting the Visual Studio Code ecosystem, including the VS Code Marketplace, OpenVSX, Cursor, and Windsurf users. Reporting in the provided content states the actor has been active for over a year and linked to at least 24 malicious extensions. WhiteCobra’s primary objective is theft of cryptocurrency wallet information, including wallet phrases and other crypto-wallet data from compromised developer systems. The content describes the actor as flooding the VS Code marketplace with crypto-stealing extensions and planting malicious extensions across VSCode and OpenVSX marketplaces. One cited incident involved Ethereum developer Zak Cole, who said his wallet was drained after using the malicious contractshark.solidity-lang extension. No additional aliases, sub-groups, or nation-state attribution are directly supported by the provided content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Abused the VS Code marketplace by publishing numerous crypto-stealing extensions; associated in the content with a malicious extension that also had basic ransomware capabilities.
Associated with flooding the VS Code Marketplace with crypto-stealing malicious extensions.
WhiteCobra is responsible for distributing malicious extensions in the VSCode and Cursor code editor marketplaces, specifically targeting cryptocurrency users to steal wallet credentials and assets.
WhiteCobra is a threat actor group focused on stealing crypto-wallet information by distributing malicious extensions on developer marketplaces such as VSCode and OpenVSX.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.