Solidity Pro VSCode Extension (Malicious)
Summary
Two malicious Visual Studio Code extensions published under the names 'Solidity Pro' by publisher accounts helper-beeps and web3devtoolsx were confirmed in August 2026 to be credential-harvesting malware targeting Web3 and Solidity developers. According to Yeeth Security and SlowMist, the extensions exfiltrated cryptocurrency wallet vaults, private keys, seed phrases, cloud API credentials, and SSH keys via Telegram bots and Cloudflare Workers, and employed multi-hour to multi-day activation delays to evade automated detection. Open VSX flagged and removed both publisher accounts on August 6-7, 2026; no official Microsoft Marketplace removal notice has been independently verified in available sources.
Connected Entities
1 entities · 10 linked investigationsTimeline(10 events)
2025-09-01
WhiteCobra threat cluster previously identified distributing LummaStealer via malicious VS Code extensions in an earlier campaign, establishing the operational pattern later applied to Solidity Pro.
The Hacker News / Yeeth Security2025-07-01
A separate malicious Solidity-themed VS Code extension on Open VSX (distinct from the Solidity Pro campaign) reportedly resulted in a $500,000 loss for one blockchain developer, according to Malpedia and Meyka reporting.
Meyka / Malpedia2026-01-01
helper-beeps.solidity-pro versions 1.0.0 through 2.4.x active as C2 dropper phase, beaconing to Cloudflare Workers to retrieve encrypted Python payloads. Exact first-publish date not confirmed in available sources.
Yeeth Security2026-06-01
Parallel malicious extension ethdevtools.solidity-language-support identified impersonating a Solidity language-support tool with clipboard-based BIP-39 seed phrase and Ethereum private key stealing functionality.
The Hacker News2026-08-06
Open VSX flags helper-beeps publisher account as malicious and removes associated extensions from the registry.
Multiple: The Hacker News, CryptoTimes, Sourcetrail2026-08-06
Yeeth Security publishes primary technical analysis: 'Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer,' documenting the full version evolution, C2 infrastructure, IOCs, and attribution to the WhiteCobra threat cluster.
Yeeth Security2026-08-07
Open VSX flags web3devtoolsx publisher account as malicious and removes associated extensions including web3devtoolsx.solidity-pro version 3.4.0.
Multiple: The Hacker News, CryptoTimes2026-08-10
The Hacker News and GBHackers publish coverage of the Solidity Pro malware campaign, citing Yeeth Security's analysis and providing broader developer-audience visibility.
The Hacker News2026-08-12
BrinzTech publishes breach alert attributing the Solidity Pro campaign to the WhiteCobra threat actor.
BrinzTech2026-08-19
SlowMist publishes independent technical analysis on Medium confirming credential-harvesting, remote payload execution, and remote update capabilities; specifically analyzes helper-beeps version 2.4.1 and web3devtoolsx version 3.4.0.
SlowMist / CryptoTimesDecision Log
- #1publish⛓ pending8/23/2026, 11:11:11 PMhash: 67eCNbnyTXx2bwhWJtMT6aTKXnbHz4UeuT6nuXQZUKv4
12 of 13 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/23/2026, 11:11:04 PM
last updated: 8/24/2026, 3:27:37 AM
avoid.net — verified advice for a post-truth world