hacker-news · Crawled Aug 10, 2026
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
5 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
A malicious Visual Studio Code extension named 'solidity-pro' has been identified as stealing cryptocurrency wallets, API keys, and credentials from developers. The threat delivers a browser wallet and credential stealer that exfiltrates sensitive data such as mnemonic phrases, SSH keys, GitHub tokens, AWS keys, and Telegram bot tokens via Telegram bots. The malware uses heavy obfuscation, delayed activation, and clean intermediate versions to evade detection by static scanners and sandbox environments.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 12 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1114.001 Local Email Collection · Collection T1078 Valid Accounts · Defense Evasion T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1555 Credentials from Password Stores · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1574.002 DLL Side-Loading · Persistence