Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware

Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad credential and cryptocurrency-wallet stealers. Yeeth Security identified two publishers, helper-beeps and web3devtoolsx, distributing related solidity-pro packages that use Solidity-themed branding, obfuscation, and version churn to target web3 developers. The campaign reflects […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: