Malicious VS Code Extensions Stealthily Steal OpenAI Keys and Crypto Wallets
TechNadu · x · 2026-08-10
Security researchers have discovered that malicious VS Code extensions targeting Solidity developers are stealing crypto wallets, GitHub/GitLab tokens, AWS credentials, OpenAI API keys, and SSH keys. These malicious plugins, such as Later Solidity Pro, use delayed activation, waiting hours or days before striking to outlast casual security reviews.
Related event: Malicious VS Code Extensions Steal OpenAI Keys(2 posts)→
More from coding & agent
- Developer Uses Codex to Automate Administrative Emails, Boosting Productivity — whoiskatrin · 2026-08-10
- Stop Prompting: Build an Autonomous Multi-Agent Team with Claude Code — PrajwalTomar_ · 2026-08-10
- galaxy-profile: Render Your GitHub Profile as an Animated Galaxy — tom_doerr · 2026-08-10
- Dev Releases Interactive Crop Node to Streamline ComfyUI Workflows — obvpm · 2026-08-10
- Shift in AI Coding Workflows: Embracing Long Context Over New Threads — JeremyNguyenPhD · 2026-08-10
- Disentangling AI Agent Authorization: Access Control vs Data Binding — Prestigious-Run-1954 · 2026-08-10