
Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host
A malicious VS Code extension named “Solidity Pro” is targeting cryptocurrency developers with a multi-stage attack chain that begins inside the editor but ends with Python malware running independently on the victim’s system. Security researchers at Yeeth Security tracked malicious packages published as helper-beeps.solidity-pro and web3devtoolsx.solidity-pro. The extensions appear to offer Solidity development, AI auditing, […]
The post Malicious VS Code Extension Drops Detached Python Payload Outside the Extension Host appeared first on Cyber Security News.