A dangerous VS Code extension called "Solidity Pro" is infiltrating cryptocurrency developers' environments with a sophisticated multi-stage attack strategy that starts within the editor but concludes on the victim's system via independent Python malware. Security experts at Yeeth Security identified malicious packages named helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, which appear to provide Solidity development, AI auditing, and gas-analysis features. However, these extensions actually download payloads, collect sensitive developer data, and transmit stolen information back to the attacker's infrastructure.
This campaign is linked to previous WhiteCobra activities, which used fake Solidity-focused extensions and marketplace manipulation targeting VS Code, Cursor, and Open VSX users. securitylabs.datadoghq+1 VS Code Payload Escape Early versions of “Solidity Pro,” ranging from v1.0.0 to v2.4.x, feature seemingly innocuous components like Web3Analytics and ApiClient.
Some samples store their payload under names resembling .vscode_sol_analytics_
IP addresses and domains are defanged to prevent accidental resolution or hyperlinking.












