SlowMist Security Team Warning: The vscode plugin “solidity pro” exhibits malicious poisoning behavior
2026-08-19 18:03:14
According to CoinMeta, Wu said that the SlowMist security team has issued a warning that a vscode plugin named “solidity pro” targeting developers of Solidity / Web3 contains malicious code. Analysis revealed that previous versions of this plugin, published under the identities of helper-beeps and web3devtoolsx, contained malicious functions such as credential theft, remote payload execution, and remote vsix updates. Although these malicious functions were removed in later versions, traces of the malicious code and the former publisher still remain in the code repository. SlowMist pointed out that detecting only the current version for security vulnerabilities may make a plugin with a history of malice appear “clean” or low-risk, emphasizing that plugin security reviews should cover multiple aspects including version history, publisher changes, build traceability, and remote control capabilities.
Source:X
This content is for market information only and does not constitute investment advice.
Follow CoinMeta official accounts to stay updated

Hot Articles
Refresh

'No longer a distant place': F2Pool Co-founder Chun Wang joins SpaceX's 2-year mission to Mars
05-22 18:25

Polymarket Targets Japan Approval Despite Gambling Laws
05-22 18:00

ZachXBT flags suspected exploit involving Polymarket's UMA adapter contract on Polygon
05-22 17:57

ZachXBT flags $520K Polymarket exploit on Polygon, team says funds are safe
05-22 17:24

Verus bridge exploiter returns 4,052 ETH, retains $2.8 million bounty: onchain analyst
05-22 17:24



