Malicious VS Code Extensions Stealthily Steal OpenAI API Keys and Crypto Wallets

TechNadu · x · 2026-08-10

Malicious VS Code extensions targeting Solidity developers have been discovered recently. These extensions are designed to remain dormant for hours or days before activation, specifically to outlast casual security reviews.

Once active, later versions of the 'Solidity Pro' extension proceed to steal crypto wallets, GitHub/GitLab tokens, AWS credentials, OpenAI API keys, and SSH keys. The two flagged extensions have been removed from Open VSX, although one associated GitHub repo remained accessible at the time of reporting.

Related event: Malicious VS Code Extensions Steal OpenAI Keys(2 posts)→

Original post →

More from Safety

Safety channel →