Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
A malicious VS Code extension, Solidity Pro, has been found stealing crypto wallets, API keys, and credentials; the two listed extensions are no longer available on Open VSX.
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code extension named Solidity Pro ("solidity-pro") that steals crypto wallets, API keys, and credentials. The two extensions involved are helper-beeps.solidity-pro and web3devtoolsx.solidity-pro. Neither is currently available on the Open VSX marketplace, though the associated GitHub repository remains a concern. The stealer targets browser-based cryptocurrency wallets and user credentials.