← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 10, 2026 · 09:56via CyberPress

Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host

Brief

A malicious VS Code extension named “Solidity Pro” is targeting cryptocurrency developers with a multi-stage attack chain that begins inside the editor but ends with Python malware running independently on the victim’s system.

Security researchers at Yeeth Security tracked malicious packages published as helper-beeps. solidity-pro and web3devtoolsx. solidity-pro .

The extensions appear to offer Solidity development, AI auditing, and gas-analysis features. Instead, they download payloads, collect sensitive developer data, and send stolen information to attacker-controlled infrastructure.

The campaign appears linked by tradecraft to the previously reported WhiteCobra activity, which used fake Solidity-focused extensions and marketplace manipulation to target VS Code, Cursor, and Open VSX users .

Read more on CyberPress