← Radar

Incident case file

Sign in to watch

Solidity Pro VS Code Extension — Web3 Developer Credential Stealer

Incident date 2026-08-05Last updated Aug 26, 2026

0 views

ContainedChain-agnostic (Web3 developer toolingsupply chain)Supply chain attack — malicious IDE extension (credential/seed harvesting, remote payload execution)Cluster: SOLPRO-SUPPLY-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

Publisher accounts: helper-beeps.solidity-pro and web3devtoolsx.solidity-pro. No individual or group attribution has been publicly confirmed.

Funds moved to

No confirmed fund theft associated with this campaign at the time of disclosure. Exfiltration targeted private keys, mnemonics, cloud tokens, and wallet vaults via obfuscated Cloudflare Workers endpoints over HTTPS POST; downstream financial impact on individual developers, if any, has not been separately quantified.

Linked

The extensions auto-updated every 30 minutes, installing new VSIX packages with no hash or signature verification, giving the publisher persistent remote control over any machine with the extension installed. A bundled 'Web3Analytics' module scanned infected machines for private keys, mnemonics, cloud tokens, and wallet vaults. Version 2.4.1 of the helper-beeps variant activated specifically inside Solidity/Hardhat/Foundry workspaces with a 24-48 hour activation delay and included anti-analysis

Chronology

1 beat
  1. Prior to Aug 6, 2026: Malicious versions of the 'Solidity Pro' extension are published under two separate marketplace accounts (helper-beeps.solidity-pro and web3devtoolsx.solidity-pro), targeting Web3/Solidity developers. Aug 6-7, 2026: Open VSX adds both extension IDs to its malicious-extension blocklist, cutting off further installs through that registry. Aug 19, 2026: SlowMist publishes a full static-analysis writeup confirming the extensions fetched AES-GCM-encrypted payloads, decrypted them client-side, wrote a Python file to disk, and executed it via Node's child_process.spawn — establishing persistent remote control through 30-minute auto-updates with no package verification. The embedded 'Web3Analytics' module is documented scanning for private keys, mnemonics, cloud tokens, and wallet vaults. Version 2.4.1 is shown to specifically target Solidity/Hardhat/Foundry project workspaces with a delayed 24-48 hour activation window and explicit anti-CI/anti-sandbox evasion logic. Recommended remediation: uninstall immediately if either extension was ever present, rotate all potentially exposed keys and credentials, and audit CI/CD environments for signs of compromise.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)