Incident case file
Sign in to watchSolidity Pro VS Code Extension — Web3 Developer Credential Stealer
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatPrior to Aug 6, 2026: Malicious versions of the 'Solidity Pro' extension are published under two separate marketplace accounts (helper-beeps.solidity-pro and web3devtoolsx.solidity-pro), targeting Web3/Solidity developers. Aug 6-7, 2026: Open VSX adds both extension IDs to its malicious-extension blocklist, cutting off further installs through that registry. Aug 19, 2026: SlowMist publishes a full static-analysis writeup confirming the extensions fetched AES-GCM-encrypted payloads, decrypted them client-side, wrote a Python file to disk, and executed it via Node's child_process.spawn — establishing persistent remote control through 30-minute auto-updates with no package verification. The embedded 'Web3Analytics' module is documented scanning for private keys, mnemonics, cloud tokens, and wallet vaults. Version 2.4.1 is shown to specifically target Solidity/Hardhat/Foundry project workspaces with a delayed 24-48 hour activation window and explicit anti-CI/anti-sandbox evasion logic. Recommended remediation: uninstall immediately if either extension was ever present, rotate all potentially exposed keys and credentials, and audit CI/CD environments for signs of compromise.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/08/19/slowmist-uncovers-targeted-poisoning-attack-in-solidity-pro-vs-code-extension/
- Articleslowmist.medium.comhttps://slowmist.medium.com/
- Articlemarketplace.visualstudio.comhttps://marketplace.visualstudio.com/
- Articleopen-vsx.orghttps://open-vsx.org/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)