Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk and SpaceX composite image with the Indian flag and Bitcoin
    India vs Elon Musk: Starlink’s Global Wall of Bans, and the Crypto Thread Running Through It
    Physical gold Bitcoin (BTC) token standing in front of the US Capitol Building and the American flag
    Why Are U.S. Government Wallets Still Routing Seized Crypto to Coinbase?
    Charlie Lee, creator of Litecoin, standing in front of a blue Litecoin corporate logo wall
    Litecoin Turns 15: Original Bitcointalk Records Show How Charlie Lee Launched LTC in 2011
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

SlowMist Uncovers Targeted Poisoning Attack in Solidity Pro VS Code Extension

The extension, available at times on Open VSX and linked to GitHub repositories, presented itself as a legitimate development aid that even referenced AI auditing and security scanning capabilities.

Written By Gopal Solanky
Edited by Divya Mistry
Published 2026-08-19·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
SlowMist Uncovers Targeted Poisoning Attack in Solidity Pro VS Code Extension

Blockchain security firm SlowMist has issued a detailed warning about malicious activity in the Solidity Pro Visual Studio Code extension, a tool marketed to Solidity and Web3 developers for features including gas queries, token price monitoring, code snippets, and compilation assistance. 

According to the firm’s analysis published on August 19, 2026, historical versions of the extension under two publisher identities contained clear credential-harvesting, remote payload execution, and remote update capabilities designed to compromise developer machines.

AI Summary
Show
Malicious versions fetched encrypted payloads, decrypted with AES‑GCM, wrote Python file, executed via Node child_process.spawn.
Extension auto‑updated every 30 minutes, installing VSIX packages without hash or signature verification, creating persistent remote control.
Web3Analytics module scanned for private keys, mnemonics, cloud tokens, wallet vaults, exfiltrating data via HTTPS POST to obfuscated Cloudflare Workers.

The extension, available at times on Open VSX and linked to GitHub repositories, presented itself as a legitimate development aid that even referenced AI auditing and security scanning capabilities. 

SlowMist’s investigation, based on static analysis of version history, build artifacts, and publisher changes without executing the samples, revealed a pattern of evolving malicious functionality followed by apparent cleanup in later releases. The two primary Extension IDs involved were helper-beeps.solidity-pro and web3devtoolsx.solidity-pro. Open VSX added both to its malicious extension control list on August 6–7, 2026.

Historical Versions Showed Credential Theft and Remote Execution

Under the helper-beeps publisher, version 2.4.1 activated in Solidity files or Hardhat/Foundry workspaces and introduced a deliberate delay of 24 to 48 hours before proceeding. After the wait, it checked for continuous-integration environment variables such as CI, GITHUB_ACTIONS, or JENKINS_HOME and exited if any were present—behavior consistent with attempts to evade automated analysis. It then requested encrypted data from remote “/firmware” endpoints, decrypted the response using AES-GCM, wrote the result as a temporary Python file, and launched it in detached mode via Node.js child_process.spawn so the payload could continue running even after the extension host closed.

Version 3.4.0 under the web3devtoolsx publisher shifted to more immediate data collection. It activated automatically on VS Code startup or when Solidity files were present. 

The Web3Analytics module, enabled by default, scanned for a wide range of sensitive material: EVM private keys and BIP39 mnemonics, browser wallet vaults (MetaMask, Phantom, Rabby, Coinbase, and others), GitHub, and GitLab tokens, AWS and other cloud credentials, SSH private keys, .env files, OpenAI and similar API keys, and Telegram bot tokens. 

The security firm noted that collected data was exfiltrated via HTTPS POST requests to obfuscated Cloudflare Workers endpoints on paths /x (JSON) and /y (multipart). In parallel, an AutoUpdater component polled remote servers every 30 minutes for new VSIX packages and installed them without hash, signature, or integrity checks, giving attackers an ongoing remote control channel.

Independent reporting from Yeeth Security and outlets including The Hacker News corroborated the presence of these capabilities across versions spanning roughly 1.0.0 to 3.x, noting the use of randomized delays, intermediate clean-looking releases to build trust, and exfiltration sometimes routed through Telegram in related samples.  

Read: Stay Ahead of Scams: Top 5 Crypto Investigators You Must Follow

Publisher Changes and Clean Releases Highlight Detection Gaps

SlowMist traced a clear engineering lineage: build artifacts under the newer web3devtoolsx identity retained residual metadata, copyright notices, and repository references from helper-beeps. A later “Clean release” commit (labeled v1.0.0 / corresponding to the examined 4.0.0 bundle) produced a package containing only ordinary features such as gas tracking and price monitoring. 

However, the GitHub source tree still contained the full malicious TypeScript modules for Web3Analytics and AutoUpdater. These were simply excluded from the final VSIX by .vscodeignore rules and by removing their imports from the main entry point. The result was a deliverable that appeared clean while the malicious code remained available for potential reintroduction.

This pattern underscores a critical limitation in current extension security practices. Scanning only the latest published version can allow an extension with a documented malicious history to reappear as low-risk after a cleanup. 

SlowMist emphasizes that effective assessment must incorporate full version history, publisher identity changes, build provenance, residual source code, and any remote update mechanisms.

Developers who installed Solidity Pro, particularly versions associated with helper-beeps or web3devtoolsx, are advised to remove the extension immediately, rotate any potentially exposed credentials, wallets, and tokens, and audit local systems for unauthorized processes or files. Marketplace metrics, such as download counts or stars, should be treated only as contextual signals, never as security guarantees. 

The incident reinforces the need for broader supply-chain scrutiny of IDE extensions that operate inside a developer’s highly privileged trust domain.

Also read: Block and Galaxy Research Give Lead to Law Enforcement in $112M Coldcard Bitcoin Theft

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BlockchainCrypto HackWeb3
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Physical gold Bitcoin coin standing beside wooden blocks spelling "TAX" in front of the flag of Greece
Greece Lowers Proposed Crypto Tax Rate to 10% in Public Consultation
Laptop screen displaying 79Vault logo next to BNB coins spilling from a wallet and a phone showing a CertiK warning symbol
79thVault Hack: $12.5M Drained From 79AU Pool on BNB Chain
Smartphone screen displaying the blue and green Standard Chartered logo and wordmark against a blurred corporate backdrop
Standard Chartered Plans Crypto and Stablecoin Custody in Singapore for Institutions
TOKEN2049 Singapore event backdrop on a dark stage displaying "1-2 October 2025 • Marina Bay Sands" with blue spotlights and audience silhouettes below
TOKEN2049 Singapore Day 2: Wall Street, Coinbase Global Exchange, Cardano’s Midnight, AI, 2027 Expansion
Physical Jupiter (JUP) token coin standing alongside a Solana (SOL) coin with a financial price candlestick chart in the background
Why Is Jupiter Price Up Today? JUP Jumps Over 16% as Solana Slips

Find Us on Socials

You may also like

Vitalik Buterin, co-founder of Ethereum, speaking on stage in a tie-dye shirt while gesturing with his hand

Vitalik Buterin Warns Against Rushed Wallet Moves as AI Raises Crypto Risks

Physical USD Coin (USDC) token standing in front of an illuminated Samsung corporate wall sign

Samsung Brings USDC to Galaxy Wallet With Coinbase, Solana & Sui

Coinbase Prime screen and official US government documents positioned in front of the US Capitol dome.

U.S. Government Moves Over $565M to Coinbase Prime in Seized Assets

Hooded hacker working on a laptop displaying Uranium Finance branding next to a system breach alert.

US Jury Convicts Uranium Finance Hacker Over $54 Million Crypto Theft

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram
© 2026 The Crypto Times | Protocols And Tokens Pvt Ltd.
DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information