Malicious VS Code Extensions Stealthily Steal OpenAI Keys and Crypto Wallets

TechNadu · x · 2026-08-10

Security researchers have discovered that malicious VS Code extensions targeting Solidity developers are stealing crypto wallets, GitHub/GitLab tokens, AWS credentials, OpenAI API keys, and SSH keys. These malicious plugins, such as Later Solidity Pro, use delayed activation, waiting hours or days before striking to outlast casual security reviews.

Related event: Malicious VS Code Extensions Steal OpenAI Keys(2 posts)→

Original post →

More from coding & agent

coding & agent channel →