Executive Summary
In August 2026, cybersecurity researchers identified malicious Visual Studio Code (VS Code) extensions named 'Solidity Pro' that targeted developers by stealing sensitive information. These extensions, including 'helper-beeps.solidity-pro' and 'web3devtoolsx.solidity-pro,' were distributed through the Open VSX registry and GitHub repositories. Early versions (1.0.0 to 2.4.x) retrieved encrypted Python payloads from Cloudflare Workers, while versions from 3.0.0 onwards evolved into full-fledged information stealers. The malware exfiltrated data such as browser profiles, cryptocurrency wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens via a Telegram bot upload. The attackers employed obfuscation techniques and delayed activation to evade detection, allowing the malicious code to execute hours or days after installation. This campaign shares similarities with the 'WhiteCobra' threat actor, known for distributing Lumma Stealer through malicious VS Code extensions in September 2025. The incident underscores the persistent threat posed by supply chain attacks targeting developer tools and the need for enhanced vigilance in extension marketplaces.
Why This Matters Now
The 'Solidity Pro' incident highlights the ongoing risk of supply chain attacks in developer ecosystems, emphasizing the need for rigorous vetting of third-party extensions and heightened awareness among developers to prevent credential theft and data exfiltration.
Attack Path Analysis
Attackers introduced malicious Visual Studio Code extensions named 'Solidity Pro' into the Open VSX marketplace, leading to the installation of these extensions by developers. Upon installation, the extensions executed obfuscated code to retrieve and run an encrypted Python payload, escalating their privileges. The malware then moved laterally within the system, accessing sensitive files and credentials. It established a command and control channel via Telegram bots to exfiltrate collected data. The exfiltrated data included browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. The impact was significant, resulting in the theft of sensitive information and potential financial losses.
Kill Chain Progression
Initial Compromise
Description
Attackers introduced malicious Visual Studio Code extensions named 'Solidity Pro' into the Open VSX marketplace, leading to the installation of these extensions by developers.
MITRE ATT&CK® Techniques
IDE Extensions
Credentials from Web Browsers
Exfiltration Over Web Service: Exfiltration to Cloud Storage
User Execution: Malicious File
Indicator Removal: File Deletion
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data Security
Control ID: Pillar 3: Data
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks targeting VS Code extensions directly compromise development environments, stealing API keys, SSH keys, and source control tokens used by software developers daily.
Information Technology/IT
IT organizations face credential theft and lateral movement risks as malicious extensions harvest AWS keys, session tokens, and infrastructure access credentials from developer workstations.
Financial Services
Cryptocurrency wallet theft and seed phrase harvesting specifically targets financial technology developers, compromising MetaMask, Coinbase, and other wallet vaults containing digital assets.
Biotechnology/Greentech
Blockchain-focused development teams in emerging tech sectors are prime targets for Solidity extension attacks, risking smart contract credentials and crypto wallet compromise.
Sources
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentialshttps://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.htmlVerified
- Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealerhttps://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-TelegramVerified
- Fake Solidity VSCode extension on Open VSX backdoors developershttps://www.bleepingcomputer.com/news/security/fake-solidity-vscode-extension-on-open-vsx-backdoors-developers/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the attacker's ability to exploit the compromised extension by enforcing strict workload isolation and segmentation.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and segmenting workloads.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict controls on internal communications.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the attacker's ability to establish command and control channels by providing comprehensive monitoring and control over network communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict outbound traffic policies.
The implementation of Aviatrix Zero Trust CNSF would likely reduce the overall impact by limiting the attacker's ability to access and exfiltrate sensitive information.
Impact at a Glance
Affected Business Functions
- Software Development
- Cryptocurrency Transactions
- Source Code Management
Estimated downtime: 7 days
Estimated loss: $500,000
Compromise of cryptocurrency wallets, API keys, SSH keys, and source-control tokens.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized access and limit lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Enforce East-West Traffic Security to monitor and control internal traffic, reducing the risk of lateral movement.
- • Apply Multicloud Visibility & Control to gain comprehensive insights into cloud environments and detect potential threats.



