Researchers reported a malicious Visual Studio Code extension campaign using the Solidity Pro name to target Solidity and Web3 developers, stealing cryptocurrency wallet data, developer secrets, and infrastructure credentials. The packages, tied to publishers including helper-beeps and web3devtoolsx, appeared in multiple releases spanning at least versions 1.0.0 through 4.0.0, with some clean-looking intermediate versions likely used to evade marketplace review. Early variants retrieved an encrypted Python payload from Cloudflare Workers after a 12- to 72-hour delay, while later versions evolved into a built-in information stealer.
The malware harvested browser data, wallet vaults, GitHub and GitLab tokens, cloud credentials, API keys, SSH private keys, Telegram bot tokens, and secrets linked to wallets including MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr, then exfiltrated the data through Telegram bot infrastructure. Researchers said the operation used obfuscation, delayed activation, polished branding, and version churn to avoid automated scanning and user suspicion, and noted related malicious VS Code and npm packages as part of a broader developer-focused supply-chain threat in open-source tooling ecosystems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In June 2026, Yeeth Security identified the malicious VS Code extension ethdevtools.solidity-language-support impersonating a Solidity language-support tool. It used delayed activation and clipboard hijacking to scrape seed phrases, Ethereum private keys, and wallet addresses, then replace copied crypto addresses with attacker-controlled ones.
Yeeth Security said WhiteCobra was previously detected distributing Lumma Stealer through malicious VS Code extensions, providing historical context for the later Solidity Pro activity.
By the time of reporting, the malicious Solidity Pro extensions were no longer available on Open VSX, indicating takedown or removal from the marketplace. The associated GitHub repository for web3devtoolsx/solidity-pro remained accessible at that time.
The reporting linked the Solidity Pro campaign to additional malicious extensions and packages, including helper-beeps.solidity-pro-ai-auditor, iktok90-design.solidity-pro, ChainDevTools.solidity-pro, NomcFoundation.hardhat-solidity, a malicious npm package named ascii-fetcher, and other VS Code extensions delivering droppers. This expanded the story from a single extension to a broader developer-focused supply-chain abuse cluster.
Starting with version 3.0.0, the malicious Solidity Pro extensions evolved from delayed downloaders into full information stealers. The newer variants harvested browser data, wallet vaults, developer tokens, cloud credentials, API keys, SSH keys, Telegram bot tokens, and crypto secrets, then exfiltrated the data via Telegram.
Early Solidity Pro releases, spanning versions 1.0.0 through at least 2.4.x, contacted Cloudflare Workers after a delay, retrieved an encrypted Python payload, and executed it outside VS Code. Yeeth Security tied these releases to publishers including helper-beeps and web3devtoolsx.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceyeethsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.