Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro that has been observed delivering a browser wallet and credential stealer.
Intelligence analysis by Llama

A malicious VS Code extension named Solidity Pro has been observed delivering a browser wallet and credential stealer. The extension has been flagged by cybersecurity researchers and users are advised to remove it.
Imagine you're using a special tool to help you with your coding work. But, unbeknownst to you, this tool is secretly stealing your important information like passwords and wallet details. This is what happened with a malicious tool called Solidity Pro. It was designed to look like a helpful tool, but it was actually a sneaky thief. Luckily, cybersecurity experts found out and warned people to remove it.
Analysis
Threat Actor Tactics and Techniques
The malicious VS Code extension, Solidity Pro, has been observed delivering a browser wallet and credential stealer. The extension has been flagged by cybersecurity researchers and users are advised to remove it. The threat actor's tactics and techniques include using a full-blown information stealer that can collect browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens. The captured data is then exfiltrated via a Telegram bot upload.
Impact on Users
Users who have installed the extensions are advised to remove them, inspect dependency graphs, block known command-and-control (C2) domains, and alert on use of cscript, mshta, cmd, curl, and powershell commands. This is not the first time threat actors have published bogus Solidity extensions across open-source ecosystems. In June 2026, Yeeth Security flagged another extension named "ethdevtools.solidity-language-support" that impersonated a Solidity language-support tool for Ethereum developers, but harbored a delayed-activation clipboard stealer to scrape BIP-39 seed phrases, Ethereum private keys, and wallet addresses.
Comparison to WhiteCobra
The cybersecurity company said the activity shares the same high-level playbook as WhiteCobra, another threat cluster that was detected in September 2025 as distributing Lumma Stealer through malicious VS Code extensions. This highlights the importance of being cautious when installing software and the need for regular security updates and patches.
Key points
- A malicious VS Code extension named Solidity Pro has been observed delivering a browser wallet and credential stealer.
- The extension has been flagged by cybersecurity researchers and users are advised to remove it.
- Users who have installed the extensions are advised to remove them, inspect dependency graphs, block known command-and-control (C2) domains, and alert on use of cscript, mshta, cmd, curl, and powershell commands.
- This is not the first time threat actors have published bogus Solidity extensions across open-source ecosystems.
- The cybersecurity company said the activity shares the same high-level playbook as WhiteCobra, another threat cluster that was detected in September 2025 as distributing Lumma Stealer through malicious VS Code extensions.
If users are cautious and remove the malicious extension, they can avoid falling victim to the credential stealer. Additionally, the discovery of this threat highlights the importance of regular security updates and patches.
The fact that threat actors have published bogus Solidity extensions across open-source ecosystems suggests that the risk of falling victim to credential stealers is still present. Users must remain vigilant and cautious when installing software.



