SlowMist Security Team Warning: The vscode plugin “solidity pro” exhibits malicious poisoning behavior
2026-08-19 18:03:14
According to CoinMeta, Wu said that the SlowMist security team has issued a warning that a vscode plugin named “solidity pro” targeting developers of Solidity / Web3 contains malicious code. Analysis revealed that previous versions of this plugin, published under the identities of helper-beeps and web3devtoolsx, contained malicious functions such as credential theft, remote payload execution, and remote vsix updates. Although these malicious functions were removed in later versions, traces of the malicious code and the former publisher still remain in the code repository. SlowMist pointed out that detecting only the current version for security vulnerabilities may make a plugin with a history of malice appear “clean” or low-risk, emphasizing that plugin security reviews should cover multiple aspects including version history, publisher changes, build traceability, and remote control capabilities.
Bullish 0
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.