← Solidity Pro VSCode Extension (Malicious)1 decision on this page
Audit log
Every state-changing event for Solidity Pro VSCode Extension (Malicious): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-23 23:11:11ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
67eCNbnyTXx2…uXQZUKv4sha256 → base58
verifying row…canonical bytes (21084 B) ▸
{"actor":"system:backfill","investigation_id":"26dc07e2-5780-4704-aa90-143adfe70acb","kind":"publish","page_slug":"solidity-pro-vscode-extension-malicious","published_at":"2026-08-23T23:11:11.876Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Solidity Pro VSCode Extension (Malicious)","sections":[{"content":"Two VS Code extension packages operating under the display name 'Solidity Pro' were identified as malware in August 2026 by Yeeth Security and subsequently analyzed by blockchain security firm SlowMist. The malicious packages were published under two distinct publisher accounts: helper-beeps (extension ID: helper-beeps.solidity-pro, with a related package helper-beeps.solidity-pro-ai-auditor) and web3devtoolsx (extension ID: web3devtoolsx.solidity-pro). A third impostor variant attributed to iktok90-design.solidity-pro was also flagged by Yeeth Security. The extensions were distributed through the Open VSX Registry. According to Yeeth Security, certain versions were built as clean decoy releases (notably v1.0.0 and v4.0.0) to establish publisher reputation before malicious payloads were introduced in intermediate versions. The GitHub repository web3devtoolsx/solidity-pro remained publicly accessible at the time of reporting in August 2026.","heading":"Overview and Publisher Identities","severity":"critical","sources":[{"credibility":2,"name":"Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer — Yeeth Security","type":"research","url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"credibility":1,"name":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html"},{"credibility":2,"name":"SlowMist: Beware of Solidity Pro — A Targeted Poisoning Attack on Web3 Developers","type":"research","url":"https://slowmist.medium.com/beware-of-solidity-pro-a-targeted-poisoning-attack-on-web3-developers-4c91a9892198"}]},{"content":"According to analysis by Yeeth Security and SlowMist, the extensions evolved across two distinct operational phases. Early versions (1.0.0 through 2.4.x) functioned as staged droppers: upon activation they beaconed to Cloudflare Worker endpoints, downloaded an AES-GCM encrypted Python payload using a static passphrase, and executed it via child_process.spawn. Versions 3.0.0 and later — including web3devtoolsx version 3.4.0 — shifted to a self-contained information stealer. The Web3Analytics module within these later versions scanned developer environments for: EVM private keys and BIP-39 mnemonic seed phrases; browser-based wallet vaults belonging to MetaMask, Phantom, Rabby, Coinbase Wallet, Trust Wallet, and Keplr; GitHub tokens (ghp_ and github_pat_ formats), GitLab tokens (glpat-), and Bitbucket credentials; AWS access keys and session tokens; Cloudflare API tokens (cfat_); OpenAI API keys (sk-, sk-proj-, sk-ant- variants); Telegram bot tokens; SSH private keys; Bitcoin WIF and extended private keys (xprv); and .env files. Harvested data was exfiltrated via HTTPS POST to obfuscated Cloudflare Workers endpoints (documented C2 fragments include violet-87cardo[.]workers[.]dev and soft-feather-7807.0x.cloudflare-workers[.]workers[.]dev) and via Telegram bot upload at the /u multipart endpoint. An AutoUpdater component present in some versions polled attacker-controlled servers every 30 minutes without hash or signature verification, enabling persistent remote control and silent payload replacement.","heading":"Malware Capabilities and Data Exfiltrated","severity":"critical","sources":[{"credibility":2,"name":"Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer — Yeeth Security","type":"research","url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"credibility":2,"name":"SlowMist: Beware of Solidity Pro — A Targeted Poisoning Attack on Web3 Developers (via CryptoTimes summary)","type":"news_article","url":"https://www.cryptotimes.io/2026/08/19/slowmist-uncovers-targeted-poisoning-attack-in-solidity-pro-vs-code-extension/"},{"credibility":2,"name":"Malicious VS Code Extensions: Stealer and Counterfeit Campaigns — Sourcetrail","type":"research","url":"https://www.sourcetrail.com/software/ide/malicious-vs-code-extensions-new-stealer-and-counterfeit-campaigns-exposed/"}]},{"content":"According to SlowMist's August 2026 analysis, version 2.4.1 under the helper-beeps publisher introduced a deliberate 24 to 48 hour activation delay that triggered only when a Solidity file was opened or a Hardhat or Foundry workspace was detected. The malware additionally checked for the presence of continuous integration environment variables and exited without executing if any were found, a behavior consistent with attempts to evade automated sandbox analysis. Subsequent versions used heavy JavaScript obfuscation — splitting strings across immediately invoked function expression (IIFE) tables — and hex-encoded C2 endpoint fragments to complicate static analysis. Method names were rotated between releases to defeat signature-based detection. The use of clean 'decoy' versions at key version numbers (v1.0.0, v4.0.0) was assessed by Yeeth Security as a reputation-building tactic to attract installs before malicious code was activated in adjacent versions.","heading":"Evasion Techniques","severity":"critical","sources":[{"credibility":2,"name":"Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer — Yeeth Security","type":"research","url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"credibility":2,"name":"SlowMist Uncovers Targeted Poisoning Attack in Solidity Pro VS Code Extension — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/19/slowmist-uncovers-targeted-poisoning-attack-in-solidity-pro-vs-code-extension/"}]},{"content":"Yeeth Security attributed the Solidity Pro campaign to a threat cluster it tracks as WhiteCobra, citing overlapping tactics with an earlier WhiteCobra sample (NomcFoundation.hardhat-solidity) that used the same encrypted C2 and external payload execution pattern. A leaked internal document referred to in reporting as 'DEPLOYMENT PLAN: Operation Solidity Pro' describes five campaign phases — packaging, deployment, promotion, inflation (artificial download count manipulation), and exfiltration — and allegedly lists revenue targets of $10,000 to $500,000 per hour. Koi Security researcher Yuval Ronen separately assessed that WhiteCobra has deployed at least 24 malicious extensions across VS Code and Open VSX registries. Malpedia lists WhiteCobra as an active threat actor with no confirmed state attribution or geographic origin as of available public records. The September 2025 WhiteCobra campaign distributed LummaStealer through VS Code extensions on Windows. No law enforcement charges or indictments relating to WhiteCobra have been publicly reported as of August 2026.","heading":"Attribution to WhiteCobra Threat Cluster","severity":"high","sources":[{"credibility":2,"name":"Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer — Yeeth Security","type":"research","url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"credibility":1,"name":"WhiteCobra floods VSCode market with crypto-stealing extensions — Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/whitecobra-floods-vscode-market-with-crypto-stealing-extensions/"},{"credibility":2,"name":"WhiteCobra (Threat Actor) — Malpedia / Fraunhofer FKIE","type":"research","url":"https://malpedia.caad.fkie.fraunhofer.de/actor/whitecobra"},{"credibility":2,"name":"WhiteCobra Threat Actor Targets Web3 Developers via Malicious Solidity Pro Extensions — BrinzTech (August 12, 2026)","type":"news_article","url":"https://www.brinztech.com/breach-alerts/brinztech-alert-whitecobra-threat-actor-targets-web3-developers-via-malicious-solidity-pro-vs-code-extensions"}]},{"content":"Open VSX added both publisher accounts — helper-beeps and web3devtoolsx — to its malicious extension control list on August 6 and August 7, 2026, respectively, according to multiple published reports. The extensions were subsequently removed from the Open VSX Registry. As of the time of reporting by The Hacker News and Sourcetrail (August 10, 2026), the GitHub repository at web3devtoolsx/solidity-pro remained publicly accessible. No independent confirmation of a parallel removal action by Microsoft from its official VS Code Marketplace has been found in available sources reviewed for this investigation. A related malicious extension, ethdevtools.solidity-language-support, which impersonated a Solidity language-support tool and delivered a clipboard-based BIP-39 seed phrase stealer, was reportedly active in June 2026 and represents a parallel campaign in the same threat surface. Separately, a prior incident in July 2025 — involving a different malicious Solidity-themed extension on Open VSX — resulted in a reported loss of approximately $500,000 for one blockchain developer, according to Malpedia and Meyka reporting; that incident predates the Solidity Pro campaign documented here and involves a distinct extension.","heading":"Marketplace Response and Current Status","severity":"high","sources":[{"credibility":1,"name":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html"},{"credibility":2,"name":"Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware — GBHackers (August 10, 2026)","type":"news_article","url":"https://gbhackers.com/fake-solidity-pro-extensions/"},{"credibility":2,"name":"Cybersecurity VSCode Extension: Malicious Solidity Plugin Found on Open VSX Marketplace — Meyka","type":"news_article","url":"https://meyka.com/blog/cybersecurity-vscode-extension-malicious-solidity-plugin-found-on-open-vsx-marketplace/"}]},{"content":"Versions confirmed as malicious or under active investigation by Yeeth Security and SlowMist include: helper-beeps.solidity-pro versions 1.0.0 through 3.2.x (versions 1.0.0 and 4.0.0 assessed as clean decoys; versions 2.4.7 and 2.4.8 used heightened obfuscation; version 2.4.1 introduced the 24-48 hour delayed activation); web3devtoolsx.solidity-pro version 3.4.0 (the infostealer variant analyzed by SlowMist). SHA-256 hashes published by Yeeth Security include 0a9da2b33c94da3f1fc02502ab3caed6e1fbe40f9115422c09103c42a9f8b3d1 for helper-beeps version 1.0.0 and 20c2a806619e1f32b3adc78689366959089d1a5de17a59a924bf477284785b5f for helper-beeps version 3.1.0. Documented C2 domains (defanged): violet-87cardo[.]workers[.]dev; cardo[.]workers[.]dev; soft-feather-7807.0x.cloudflare-workers[.]workers[.]dev. Subdomain fragments noted: cold-peak-60871, steel-mere-orker, richardorichp, 0x0gnx0.","heading":"Affected Versions and Indicators of Compromise","severity":"critical","sources":[{"credibility":2,"name":"Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer — Yeeth Security","type":"research","url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"credibility":2,"name":"SlowMist Uncovers Targeted Poisoning Attack in Solidity Pro VS Code Extension — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/19/slowmist-uncovers-targeted-poisoning-attack-in-solidity-pro-vs-code-extension/"}]},{"content":"Security researchers including SlowMist and Yeeth Security advise the following steps for any developer who installed Solidity Pro under either the helper-beeps or web3devtoolsx publisher accounts. First, uninstall all affected extensions immediately. Second, treat any private key, mnemonic seed phrase, or wallet vault that was present on an affected machine as fully compromised and transfer any associated funds to a freshly generated wallet that has never touched the affected machine. Third, rotate all cloud credentials and API keys that were stored locally or in .env files, including AWS, Cloudflare, GitHub, GitLab, OpenAI, and Telegram bot tokens. Fourth, audit SSH authorized keys and revoke any keys that may have been exposed. Fifth, review system processes and startup items for persistence mechanisms, including detached Python processes or scheduled tasks that may have survived extension removal. Organizations should implement VS Code extension allowlists and monitor for execution of cscript, mshta, cmd, curl, and PowerShell spawned from the VS Code extension host process.","heading":"Remediation Guidance","severity":"high","sources":[{"credibility":2,"name":"SlowMist Uncovers Targeted Poisoning Attack in Solidity Pro VS Code Extension — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/19/slowmist-uncovers-targeted-poisoning-attack-in-solidity-pro-vs-code-extension/"},{"credibility":2,"name":"Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/malicious-solidity-pro-vs-code-extension/"},{"credibility":2,"name":"Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host — CyberPress","type":"research","url":"https://cyberpress.org/vs-code-payload-escape/"}]}],"sources_used":[{"credibility":2,"name":"Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer — Yeeth Security","type":"research","url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"credibility":1,"name":"Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html"},{"credibility":2,"name":"Beware of Solidity Pro: A Targeted Poisoning Attack on Web3 Developers — SlowMist (Medium)","type":"research","url":"https://slowmist.medium.com/beware-of-solidity-pro-a-targeted-poisoning-attack-on-web3-developers-4c91a9892198"},{"credibility":2,"name":"SlowMist Uncovers Targeted Poisoning Attack in Solidity Pro VS Code Extension — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/19/slowmist-uncovers-targeted-poisoning-attack-in-solidity-pro-vs-code-extension/"},{"credibility":2,"name":"Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware — GBHackers","type":"news_article","url":"https://gbhackers.com/fake-solidity-pro-extensions/"},{"credibility":2,"name":"Malicious VS Code Extensions: Stealer and Counterfeit Campaigns — Sourcetrail","type":"research","url":"https://www.sourcetrail.com/software/ide/malicious-vs-code-extensions-new-stealer-and-counterfeit-campaigns-exposed/"},{"credibility":1,"name":"WhiteCobra floods VSCode market with crypto-stealing extensions — Bleeping Computer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/whitecobra-floods-vscode-market-with-crypto-stealing-extensions/"},{"credibility":2,"name":"WhiteCobra (Threat Actor) — Malpedia / Fraunhofer FKIE","type":"research","url":"https://malpedia.caad.fkie.fraunhofer.de/actor/whitecobra"},{"credibility":2,"name":"WhiteCobra Threat Actor Targets Web3 Developers via Malicious Solidity Pro Extensions — BrinzTech","type":"news_article","url":"https://www.brinztech.com/breach-alerts/brinztech-alert-whitecobra-threat-actor-targets-web3-developers-via-malicious-solidity-pro-vs-code-extensions"},{"credibility":2,"name":"Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/malicious-solidity-pro-vs-code-extension/"},{"credibility":2,"name":"Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host — CyberPress","type":"research","url":"https://cyberpress.org/vs-code-payload-escape/"},{"credibility":2,"name":"Cybersecurity VSCode Extension: Malicious Solidity Plugin Found on Open VSX Marketplace — Meyka","type":"news_article","url":"https://meyka.com/blog/cybersecurity-vscode-extension-malicious-solidity-plugin-found-on-open-vsx-marketplace/"},{"credibility":2,"name":"Malicious IoliteLabs VSCode Extensions Target Solidity Developers — StepSecurity","type":"research","url":"https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor"}],"summary":"Two malicious Visual Studio Code extensions published under the names 'Solidity Pro' by publisher accounts helper-beeps and web3devtoolsx were confirmed in August 2026 to be credential-harvesting malware targeting Web3 and Solidity developers. According to Yeeth Security and SlowMist, the extensions exfiltrated cryptocurrency wallet vaults, private keys, seed phrases, cloud API credentials, and SSH keys via Telegram bots and Cloudflare Workers, and employed multi-hour to multi-day activation delays to evade automated detection. Open VSX flagged and removed both publisher accounts on August 6-7, 2026; no official Microsoft Marketplace removal notice has been independently verified in available sources.","timeline":[{"date":"2025-09-01","event":"WhiteCobra threat cluster previously identified distributing LummaStealer via malicious VS Code extensions in an earlier campaign, establishing the operational pattern later applied to Solidity Pro.","source":"The Hacker News / Yeeth Security","source_url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"date":"2025-07-01","event":"A separate malicious Solidity-themed VS Code extension on Open VSX (distinct from the Solidity Pro campaign) reportedly resulted in a $500,000 loss for one blockchain developer, according to Malpedia and Meyka reporting.","source":"Meyka / Malpedia","source_url":"https://meyka.com/blog/cybersecurity-vscode-extension-malicious-solidity-plugin-found-on-open-vsx-marketplace/"},{"date":"2026-01-01","event":"helper-beeps.solidity-pro versions 1.0.0 through 2.4.x active as C2 dropper phase, beaconing to Cloudflare Workers to retrieve encrypted Python payloads. Exact first-publish date not confirmed in available sources.","source":"Yeeth Security","source_url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"date":"2026-06-01","event":"Parallel malicious extension ethdevtools.solidity-language-support identified impersonating a Solidity language-support tool with clipboard-based BIP-39 seed phrase and Ethereum private key stealing functionality.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html"},{"date":"2026-08-06","event":"Open VSX flags helper-beeps publisher account as malicious and removes associated extensions from the registry.","source":"Multiple: The Hacker News, CryptoTimes, Sourcetrail","source_url":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html"},{"date":"2026-08-06","event":"Yeeth Security publishes primary technical analysis: 'Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer,' documenting the full version evolution, C2 infrastructure, IOCs, and attribution to the WhiteCobra threat cluster.","source":"Yeeth Security","source_url":"https://yeethsecurity.com/blog/2026-08-06-Solidity-Pro-WhiteCobra-C2-to-Telegram"},{"date":"2026-08-07","event":"Open VSX flags web3devtoolsx publisher account as malicious and removes associated extensions including web3devtoolsx.solidity-pro version 3.4.0.","source":"Multiple: The Hacker News, CryptoTimes","source_url":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html"},{"date":"2026-08-10","event":"The Hacker News and GBHackers publish coverage of the Solidity Pro malware campaign, citing Yeeth Security's analysis and providing broader developer-audience visibility.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/solidity-pro-vs-code-extensions-steal.html"},{"date":"2026-08-12","event":"BrinzTech publishes breach alert attributing the Solidity Pro campaign to the WhiteCobra threat actor.","source":"BrinzTech","source_url":"https://www.brinztech.com/breach-alerts/brinztech-alert-whitecobra-threat-actor-targets-web3-developers-via-malicious-solidity-pro-vs-code-extensions"},{"date":"2026-08-19","event":"SlowMist publishes independent technical analysis on Medium confirming credential-harvesting, remote payload execution, and remote update capabilities; specifically analyzes helper-beeps version 2.4.1 and web3devtoolsx version 3.4.0.","source":"SlowMist / CryptoTimes","source_url":"https://www.cryptotimes.io/2026/08/19/slowmist-uncovers-targeted-poisoning-attack-in-solidity-pro-vs-code-extension/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 0f7febc5-23bc-4931-8bf5-783a4f32f9ad
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.