吴说区块链|Aug 19, 2026 10:04
According to WuShuo, the SlowMist security team has issued a warning about a malicious supply chain attack targeting Solidity/Web3 developers through a VSCode plugin called 'Solidity Pro.' Analysis reveals that historical versions of this plugin, published under the identities of helper-beeps and web3devtoolsx, contained malicious features such as credential theft, remote payload execution, and remote VSIX updates. Although these malicious features were removed in later versions, traces of malicious code and previous publishers' footprints still remain in the codebase. SlowMist pointed out that only scanning the current version creates a security blind spot, potentially making plugins with a malicious history appear 'clean' or low-risk. They emphasized that plugin security reviews should cover multiple dimensions, including version history, publisher changes, build traceability, and remote control risks.
https://(wublock123.com)/news/slowmist-solidity-pro-vscode-plugin-supply-chain-poisoning-solidity-web3-developers-66809
Share To
HotFlash
APP
X
Telegram
CopyLink