
Malicious Solidity VS Code Extensions Steal Wallets and Keys
Cybersecurity researchers flagged malicious VS Code extensions named 'solidity-pro' that evolve from loader to information stealer, capable of harvesting browser profiles, crypto wallets, API keys, SSH keys, and Telegram bot tokens, exfiltrating data via a Telegram bot; they use obfuscation and delayed activation to evade detection, with similar incidents in the past. Users should remove the extensions, review dependencies, block known C2 domains, and monitor for risky command usage.
