Solidity Pro VS Code extensions found stealing wallets and credentials
Source headline: Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Intelligence Summary
Security researchers report that a malicious VS Code extension called Solidity Pro can steal sensitive information. The extension is associated with harvesting browser wallet data, API keys, and other credentials. It has been observed distributing a wallet and credential stealing component. Affected users are those who installed the extension from third-party sources or earlier availability channels. Even if the extension is no longer listed on Open VSX, systems already infected may require investigation and remediation. Users should uninstall the extension and rotate potentially exposed secrets immediately.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.