Researchers reported a malicious Visual Studio Code extension campaign using the Solidity Pro name to target Solidity and Web3 developers, stealing cryptocurrency wallet data, developer secrets, and infrastructure credentials. The packages, tied to publishers including helper-beeps and web3devtoolsx, appeared in multiple releases spanning at least versions 1.0.0 through 4.0.0, with some clean-looking intermediate versions likely used to evade marketplace review. Early variants retrieved an encrypted Python payload from Cloudflare Workers after a 12- to 72-hour delay, while later versions evolved into a built-in information stealer.
The malware harvested browser data, wallet vaults, GitHub and GitLab tokens, cloud credentials, API keys, SSH private keys, Telegram bot tokens, and secrets linked to wallets including MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr, then exfiltrated the data through Telegram bot infrastructure. Researchers said the operation used obfuscation, delayed activation, polished branding, and version churn to avoid automated scanning and user suspicion, and noted related malicious VS Code and npm packages as part of a broader developer-focused supply-chain threat in open-source tooling ecosystems.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
In June 2026, Yeeth Security identified the malicious VS Code extension ethdevtools.solidity-language-support impersonating a Solidity language-support tool. It used delayed activation and clipboard hijacking to scrape seed phrases, Ethereum private keys, and wallet addresses, then replace copied crypto addresses with attacker-controlled ones.
Yeeth Security said WhiteCobra was previously detected distributing Lumma Stealer through malicious VS Code extensions, providing historical context for the later Solidity Pro activity.
By the time of reporting, the malicious Solidity Pro extensions were no longer available on Open VSX, indicating takedown or removal from the marketplace. The associated GitHub repository for web3devtoolsx/solidity-pro remained accessible at that time.
The reporting linked the Solidity Pro campaign to additional malicious extensions and packages, including helper-beeps.solidity-pro-ai-auditor, iktok90-design.solidity-pro, ChainDevTools.solidity-pro, NomcFoundation.hardhat-solidity, a malicious npm package named ascii-fetcher, and other VS Code extensions delivering droppers. This expanded the story from a single extension to a broader developer-focused supply-chain abuse cluster.
Starting with version 3.0.0, the malicious Solidity Pro extensions evolved from delayed downloaders into full information stealers. The newer variants harvested browser data, wallet vaults, developer tokens, cloud credentials, API keys, SSH keys, Telegram bot tokens, and crypto secrets, then exfiltrated the data via Telegram.
Early Solidity Pro releases, spanning versions 1.0.0 through at least 2.4.x, contacted Cloudflare Workers after a delay, retrieved an encrypted Python payload, and executed it outside VS Code. Yeeth Security tied these releases to publishers including helper-beeps and web3devtoolsx.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceyeethsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.