Malicious VS Code Extensions Stealthily Steal OpenAI API Keys and Crypto Wallets
TechNadu · x · 2026-08-10
Malicious VS Code extensions targeting Solidity developers have been discovered recently. These extensions are designed to remain dormant for hours or days before activation, specifically to outlast casual security reviews.
Once active, later versions of the 'Solidity Pro' extension proceed to steal crypto wallets, GitHub/GitLab tokens, AWS credentials, OpenAI API keys, and SSH keys. The two flagged extensions have been removed from Open VSX, although one associated GitHub repo remained accessible at the time of reporting.
Related event: Malicious VS Code Extensions Steal OpenAI Keys(2 posts)→
More from Safety
- Researcher Reframes Model Distillation as a Classic Privacy Attack — maksym_andr · 2026-08-12
- Bittensor SN61 Launches Challenge to Filter Malicious AI Traffic via Red Team Attacks — bittingthembits · 2026-08-12
- Vulnerability Found: Frontier AI Models' Encrypted Reasoning Traces Can Be Extracted — AccBalanced · 2026-08-12
- Stanford HAI Calls for Stricter Data Broker Regulations to Prevent AI Privacy Abuse — StanfordHAI · 2026-08-12
- LessWrong Article Discusses: Current AIs Still Have Clear Flaws in Basic Alignment — dpaleka · 2026-08-12
- Caught in the CoT: AI Models Weigh the Risks of Cheating — _dsevero · 2026-08-12