Solidity Pro VS Code extension browser wallet and credential stealer
Malware Activity
Summary
Hide ▲
Show ▼
The Solidity Pro VS Code extension is now flagged as a browser wallet and credential stealer, exposing VS Code users to crypto theft and account compromise. Early versions 1.0.0 through v2.4.x fetched and ran an encrypted payload from Cloudflare Workers, while v3.0.0 and later versions shifted to broader credential theft. The stealer can harvest browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. It then exfiltrates the loot through a Telegram bot and uses heavy obfuscation plus delayed activation to evade review and sandboxing.
Related Happenings
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware Activity
H score29
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware ActivityAbout this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
Campaign
H score32
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
CampaignAbout this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Gremlin stealer modular toolkit evolution
Malware Activity
H score21
First: 15.05.2026 17:19
Last: 15.05.2026 17:19
Sources 1
About this happening:
The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Gremlin stealer modular toolkit evolution
Malware ActivityAbout this happening: The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Storm infostealer server-side decryption activity
Malware Activity
H score18
First: 02.04.2026 17:15
Last: 02.04.2026 17:15
Sources 1
About this happening:
The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Storm infostealer server-side decryption activity
Malware ActivityAbout this happening: The Storm infostealer now steals browser credentials, session cookies, and crypto wallets and forwards them to attacker infrastructure for server-side decryption...
Venom Stealer MaaS infostealer with persistent credential harvesting
Malware Activity
H score29
First: 31.03.2026 17:51
Last: 31.03.2026 17:51
Sources 1
About this happening:
The Venom Stealer infostealer now ships as malware-as-a-service (MaaS), expanding access to a persistent credential-theft tool and raising risk for Windows users. It s...
Venom Stealer MaaS infostealer with persistent credential harvesting
Malware ActivityAbout this happening: The Venom Stealer infostealer now ships as malware-as-a-service (MaaS), expanding access to a persistent credential-theft tool and raising risk for Windows users. It s...
Timeline
-
10.08.2026 10:38 2 articles · 1h ago
Solidity Pro VS Code extension delivers a browser wallet and credential stealer
Initial DisclosureResearchers flagged the malicious Microsoft Visual Studio Code extension Solidity Pro (`solidity-pro`), which was observed delivering a browser wallet and credential stealer. Early builds 1.0.0 through v2.4.x beaconed to Cloudflare Workers to fetch and execute an encrypted Python payload, and versions starting with v3.0.0 shifted to harvesting browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens before exfiltrating the data via a Telegram bot.
Show sources
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials — thehackernews.com — 10.08.2026 10:38
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials — thehackernews.com — 10.08.2026 10:38