Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host
Brief
A malicious VS Code extension named “Solidity Pro” is targeting cryptocurrency developers with a multi-stage attack chain that begins inside the editor but ends with Python malware running independently on the victim’s system.
Security researchers at Yeeth Security tracked malicious packages published as helper-beeps. solidity-pro and web3devtoolsx. solidity-pro .
The extensions appear to offer Solidity development, AI auditing, and gas-analysis features. Instead, they download payloads, collect sensitive developer data, and send stolen information to attacker-controlled infrastructure.
The campaign appears linked by tradecraft to the previously reported WhiteCobra activity, which used fake Solidity-focused extensions and marketplace manipulation to target VS Code, Cursor, and Open VSX users .
