
Malicious VS Code Extensions Target Solidity Developers to Steal Crypto Wallet Data and Credentials
Generalcybersecuritymalware
Two malicious Visual Studio Code extensions masquerading as Solidity development tools were used to steal browser-based cryptocurrency wallet data, API keys, and credentials. The extensions targeted developers working with Solidity, a programming language for smart contracts. The incident highlights supply chain risks associated with extension marketplaces, where a single installation could expose sensitive information. No specific dates, version numbers, or CVE identifiers were provided in the report. The attack vector relied on social engineering to deceive users into installing the malicious extensions.