SlowMist
SlowMist|Aug 19, 2026 07:10
🚨 Beware of Solidity Pro: A Targeted Poisoning Attack on #Web3 Developers SlowMist Security Team has identified malicious activity in Solidity Pro, a #VSCode extension targeting #Solidity/Web3 developers. Historical versions under two publisher identities, helper-beeps and web3devtoolsx, were found to contain credential harvesting, remote payload execution, and remote VSIX update capabilities. Interestingly, these malicious capabilities disappeared from subsequent versions, while malicious source code and traces of the previous publisher remained in the repository. We traced the version history, publisher migration, and build artifacts, highlighting a key detection blind spot: Current-version-only detection may cause extensions with a malicious history to appear clean or low-risk again. This case highlights why #ExtensionSecurity should go beyond a single file or version, incorporating version history, publisher changes, build provenance, and remote control planes. Read the full analysis 👇 https://slowmist.medium.com/beware-of-solidity-pro-a-targeted-poisoning-attack-on-web3-developers-4c91a9892198(SlowMist)
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads