The Latest Crypto News
Friday, 25 September 2026 BTC -- / --
🔍

Solidity Pro VSCode extension contains hidden malware for Web3 developers

Make The Latest Crypto News preferred on Google
Code editor window with red malware alert over an Ethereum coin symbol.
Code editor window with red malware alert over an Ethereum coin symbol.

Security firm SlowMist has discovered malicious features in Solidity Pro, a popular extension for the VSCode code editor aimed at developers working with Solidity and Web3. Earlier versions of the extension, released under two different publisher accounts, contained code designed to steal credentials, execute code remotely and update itself undetected. The extension claims to be used by more than 100,000 blockchain developers.

In brief:

  • Earlier versions of Solidity Pro contained code to steal sensitive data, including wallet data, SSH keys and environment variables.
  • The malicious features disappeared from later versions, but traces of the old publisher can still be found in the source code.
  • SlowMist warns that security scans which only check the current version will not detect this type of attack.

Data stolen via telemetry and automatic updates

According to SlowMist’s research, the extension immediately collected sensitive information from the developer’s system upon activation. The Web3Analytics module sent data about wallets, repositories, cloud storage, SSH keys, environment variables and tokens to external servers via two channels: a standard HTTPS POST and a multipart form.

At the same time, an AutoUpdater module started that checked every thirty minutes whether a new version was available. Those updates were installed without hash or signature verification, allowing attackers to distribute modified code to infected systems at any time.

A third mechanism, found in an earlier version under the publisher name helper-beeps, activated specifically when Solidity files were opened in Hardhat or Foundry projects. After a random delay of 24 to 48 hours, the extension checked whether the system was running in a CI environment such as GitHub Actions or Jenkins. If that was not the case, it retrieved encrypted code from an external server, decrypted it with AES-GCM and executed a temporary Python script that removed itself after approximately 60 seconds.

Malicious code disappeared, but traces remained

SlowMist states that the malicious features are no longer present in later versions of Solidity Pro. Nevertheless, references to the earlier publisher and old code can still be found in the current source code on GitHub. The extension has since been published under a third publisher account, MydzCP.

That makes detection difficult, says SlowMist. Security tools that only analyse the most recent version of an extension do not see the malicious history. According to SlowMist’s full report, this is a blind spot in extension security: an extension that was previously infected can be assessed as safe again after a clean update.

SlowMist calls on security researchers and platform administrators to also take version history, publisher changes, build provenance and external update mechanisms into account when assessing extensions. Developers who have installed Solidity Pro are advised to remove the extension immediately and check their credentials, SSH keys and environment variables for misuse.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Altcoin News

More news ›