Back to News
Cybersecurity

Malicious VS Code Extensions Target Crypto Assets and Credentials

Cybersecurity researchers warn that the Solidity Pro VS Code extensions are stealing sensitive information from users.

Recent findings from cybersecurity researchers have raised alarms over a malicious Visual Studio Code (VS Code) extension named Solidity Pro, which has been linked to the theft of cryptocurrency wallets, API keys, and user credentials. The extensions, identified as helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, were found to deliver a browser wallet and credential stealer. Although these extensions have been removed from Open VSX, they were previously available on platforms like GitHub, prompting concerns about their potential impact on developers and businesses using these tools.

For businesses, the implications are significant: the presence of such malicious extensions underscores the need for rigorous vetting of third-party tools and the importance of employee education on cybersecurity best practices. Companies that rely on VS Code for development should implement strict security protocols, such as using verified extensions only and maintaining up-to-date security software. This incident highlights the broader vulnerability in the software development ecosystem, where trusted platforms can be exploited to compromise sensitive information. As the integration of AI in cybersecurity becomes more prevalent, the need for advanced detection mechanisms to identify and mitigate such threats is critical, emphasizing the intersection of cybersecurity and technology innovation.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html)*