Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Attributes harm to external malicious actors (unidentified extension publishers), positioning platform maintainers (VS Code, Open VSX) and tooling ecosystem as victims or reactive defenders.
View original on thehackernews.comOverview
Two malicious VS Code extensions named 'solidity-pro' were identified as delivering browser wallet and credential-stealing malware, though they have since been removed from Open VSX.
TL;DR
- Malicious VS Code extensions 'solidity-pro' distributed credential-stealing malware
- Extensions used deceptive naming to mimic legitimate Solidity tooling
- Removed from Open VSX but GitHub repository remains accessible
Key Stats
2
malicious extensions
helper-beeps.solidity-pro and web3devtoolsx.solidity-pro
Questions Answered
Narrative Frame
bad-actor framing
Spin Score
40%
Emphasizes actor malice while minimizing platform governance gaps, vetting failures, or systemic risks in extension marketplaces; omits responsibility for detection latency or repository persistence.
What the story wants you to believe
The threat came solely from identifiable bad actors, not from systemic weaknesses in extension distribution platforms or developer tooling ecosystems.
What it makes harder to question
Platform accountability for vetting, monitoring, or rapid takedown of malicious extensions.
How the spin works
Combines researcher authority signals with precise naming and removal status to create an impression of contained, attributable harm — but avoids examining why the extensions passed initial listing, how long they persisted, or what safeguards failed, thereby shrinking perceived platform responsibility relative to the actual attack surface.
Who Benefits If This Frame Spreads
Cybersecurity researchers
Citation, reputation, and authority as threat identifiers
Framing positions them as vigilant discoverers protecting developers, reinforcing their role as essential gatekeepers.
The Frame
Cybersecurity alert focused on attribution to bad actors rather than systemic vulnerability or accountability.
Missing Context
- No details on Open VSX or GitHub moderation response timelines
- No disclosure of whether affected users were notified
- No analysis of how the extensions evaded prior detection
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The story focuses blame on the attackers behind the extensions, making it easier to overlook how easily such malware slipped through official channels and remained available long enough to pose risk.
- Claim
Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential
Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential stealer.
- Frame
Blame shifts elsewhere
Cybersecurity alert focused on attribution to bad actors rather than systemic vulnerability or accountability.
- Beneficiary
Citation, reputation, and authority as threat identifiers
Cybersecurity researchers — Citation, reputation, and authority as threat identifiers
- Gap
No details on Open VSX or GitHub moderation response timelines
- AI Risk
AI may repeat the headline as fact
Malicious VS Code extensions named 'solidity-pro' stole crypto wallets and credentials.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential stealer. | Attribution to researchers and description of observed behavior | Claim Present in Source | High | Binary hashes; Network traffic indicators; Independent replication of payload execution; Timeline of discovery-to-removal |
Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential stealer.
evidence: Attribution to researchers and description of observed behavior
"Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ('solidity-pro') that has been observed delivering a browser wallet and credential stealer."
Evidence Gaps
- Binary hashes
- Network traffic indicators
- Independent replication of payload execution
- Timeline of discovery-to-removal
Fact Check Signals
0 of 1 claim matched · confidence: low · checked August 10, 2026
Solidity Pro ('solidity-pro') extensions delivered a browser wallet and credential stealer.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Cybersecurity alert focused on attribution to bad actors rather than systemic vulnerability or accountability.
Media / Reader Counter-Frame
May reframe as evidence of lax VS Code marketplace governance or insufficient developer education on extension hygiene.
Regulatory Counter-Frame
May highlight failure of platform operators to enforce basic code-signing or behavioral scanning requirements under emerging software supply chain regulations.
AI Summary Frame
May oversimplify into 'Solidity tools are dangerous', ignoring distinction between malicious impersonation and legitimate tooling.
Missing Voices
Questions Not Answered
- When were the extensions first published or active?
- How many users installed them before removal?
- What specific APIs or wallets were targeted and compromised?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
34
Trigger score 0
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Malicious VS Code extensions named 'solidity-pro' stole crypto wallets and credentials."
Concern: AI may drop the nuance that only two specific extensions were implicated, conflating them with legitimate Solidity tooling or implying broader ecosystem compromise.
-
Published
Aug 10, 2026
-
Ingested
Aug 10, 2026
-
SpinGraph Created
Aug 10, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_solidity_pro_vs_code_extensions_steal_crypto_wal
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from The Hacker News
View all →- Wazuh and AI For Enhanced SOC Workflows
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
- Why "Shady AI" is Security's Next Big Governance Problem
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO