Skip to main content
AVOID.NET

Solidity Pro VSCode Extension (Malicious)

avoid.net/solidity-pro-vscode-extension-malicious→0/100·92% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·ELmFGh…E7rM
last updated 2026-08-25

Summary

Two malicious Visual Studio Code extensions published under the names 'Solidity Pro' by publisher accounts helper-beeps and web3devtoolsx were confirmed in August 2026 to be credential-harvesting malware targeting Web3 and Solidity developers. According to Yeeth Security and SlowMist, the extensions exfiltrated cryptocurrency wallet vaults, private keys, seed phrases, cloud API credentials, and SSH keys via Telegram bots and Cloudflare Workers, and employed multi-hour to multi-day activation delays to evade automated detection. Open VSX flagged and removed both publisher accounts on August 6-7, 2026; no official Microsoft Marketplace removal notice has been independently verified in available sources.

Connected Entities

6 entities · 60 linked investigations
Organizations
□Ethereum64□Trust Wallet□Solidity Pro VSCode Extension (Malicious)□Phantom Wallet
Tokens
♦Coinbase♦Bitcoin
Relationships
  • Solidity Pro VSCode Extension (Malicious)→mentioned with→Phantom Wallet(60%)
  • Ethereum→mentioned with→Coinbase(60%)
  • Ethereum→mentioned with→Bitcoin(60%)
  • Solidity Pro VSCode Extension (Malicious)→mentioned with→Bitcoin(60%)
  • Solidity Pro VSCode Extension (Malicious)→mentioned with→Ethereum(60%)
  • Solidity Pro VSCode Extension (Malicious)→mentioned with→Coinbase(70%)
  • Phantom Wallet→mentioned with→Ethereum(70%)
  • Phantom Wallet→mentioned with→Bitcoin(70%)
  • Phantom Wallet→mentioned with→Coinbase(60%)
  • Trust Wallet→mentioned with→Bitcoin(60%)
  • + 3 more
Have evidence about Solidity Pro VSCode Extension (Malicious)?

Timeline(10 events)

September 2025

WhiteCobra threat cluster previously identified distributing LummaStealer via malicious VS Code extensions in an earlier campaign, establishing the operational pattern later applied to Solidity Pro.

The Hacker News / Yeeth Security

July 2025

A separate malicious Solidity-themed VS Code extension on Open VSX (distinct from the Solidity Pro campaign) reportedly resulted in a $500,000 loss for one blockchain developer, according to Malpedia and Meyka reporting.

Meyka / Malpedia

2026

helper-beeps.solidity-pro versions 1.0.0 through 2.4.x active as C2 dropper phase, beaconing to Cloudflare Workers to retrieve encrypted Python payloads. Exact first-publish date not confirmed in available sources.

Yeeth Security

June 2026

Parallel malicious extension ethdevtools.solidity-language-support identified impersonating a Solidity language-support tool with clipboard-based BIP-39 seed phrase and Ethereum private key stealing functionality.

The Hacker News

6 August 2026

Open VSX flags helper-beeps publisher account as malicious and removes associated extensions from the registry.

Multiple: The Hacker News, CryptoTimes, Sourcetrail

6 August 2026

Yeeth Security publishes primary technical analysis: 'Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer,' documenting the full version evolution, C2 infrastructure, IOCs, and attribution to the WhiteCobra threat cluster.

Yeeth Security

7 August 2026

Open VSX flags web3devtoolsx publisher account as malicious and removes associated extensions including web3devtoolsx.solidity-pro version 3.4.0.

Multiple: The Hacker News, CryptoTimes

10 August 2026

The Hacker News and GBHackers publish coverage of the Solidity Pro malware campaign, citing Yeeth Security's analysis and providing broader developer-audience visibility.

The Hacker News

12 August 2026

BrinzTech publishes breach alert attributing the Solidity Pro campaign to the WhiteCobra threat actor.

BrinzTech

19 August 2026

SlowMist publishes independent technical analysis on Medium confirming credential-harvesting, remote payload execution, and remote update capabilities; specifically analyzes helper-beeps version 2.4.1 and web3devtoolsx version 3.4.0.

SlowMist / CryptoTimes
Provenance & Audit Trail

Decision Log

  • #3review revise-5Recorded on Solana ✓8/25/2026, 2:59:32 AM
    slot 443510613 · hash C9mdj8CJtejvoWbi7JkYepGYJma9mLGhHA3wBZQkUnLZ
  • #2reviewRecorded on Solana ✓8/25/2026, 2:59:32 AM
    slot 443510608 · hash 77G75keGADtLuYoEdiTXQD1mY7eCBwV1VVki7cns8uGY
  • #1publishRecorded on Solana ✓8/23/2026, 11:11:11 PM
    slot 443510034 · hash 67eCNbnyTXx2bwhWJtMT6aTKXnbHz4UeuT6nuXQZUKv4

This investigation is cryptographically anchored to the Solana blockchain (3 decisions). 12 of 13 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/23/2026, 11:11:04 PM

last updated: 8/25/2026, 2:59:32 AM

6 views

avoid.net — verified advice for a post-truth world