ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Repair Hacked Website
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Malicious VS Code Extensions Target Crypto Developers: What to Do

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Malicious VS Code Extensions Target Crypto De...
  • All articles
  • Categories
  • Tags
  • Statuses

Malicious VS Code Extensions Target Crypto Developers: What to Do

When Developer Tools Turn Against YouIn the fast-paced world of Web3 and smart contract development, Visual Studio Code extensions are indispensable....

When Developer Tools Turn Against You

In the fast-paced world of Web3 and smart contract development, Visual Studio Code extensions are indispensable. They promise to streamline your workflow, but what happens when a seemingly helpful tool is actually a trojan horse? Recent reports have uncovered two malicious extensions disguised as Solidity utilities, designed to steal sensitive data from developers' machines. This incident is a stark reminder that the software supply chain is only as strong as its weakest link—and sometimes, that link is a simple extension installation.

Illustration of a shadowy hand reaching for a digital wallet on a laptop screen

The Anatomy of the Attack

Security researchers identified two extensions, both named “Solidity Pro”, available in the VS Code marketplace. They were crafted to appeal to developers working with Solidity and the broader Web3 ecosystem. However, their real purpose was far more sinister: to harvest information from the victim's browser, including crypto wallet data, saved credentials, API keys, and other secrets commonly found in a development environment. The extensions operated under the identifiers helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, making them appear legitimate at first glance.

This is a classic supply chain attack. Instead of exploiting complex vulnerabilities, the attackers relied on social engineering and the trust developers place in the extension marketplace. Once installed, the malicious code could silently exfiltrate data, potentially leading to unauthorized access to repositories, cloud services, and even direct theft of cryptocurrency funds.

Why Developers Are Prime Targets

Developers, especially those working on blockchain projects, are attractive targets because their machines are treasure troves of sensitive information. They often have access to:

  • Environment files containing database credentials and API secrets.
  • SSH keys for remote server access.
  • Browser profiles logged into crypto exchanges and wallets.
  • Cloud service tokens with broad permissions.

A single compromised extension can expose all of these, giving attackers a foothold for lateral movement within an organization. The impact goes beyond the individual developer; it can jeopardize entire projects and client data.

Immediate Steps to Mitigate the Threat

If you or your team have installed either of these malicious extensions, act immediately:

  • Uninstallhelper-beeps.solidity-pro and web3devtoolsx.solidity-pro from all VS Code instances.
  • Rotate all credentials that were accessible from the affected machine. This includes API keys, passwords, and tokens. Assume they are compromised.
  • Review recent account activity for any unauthorized access, especially on cloud platforms and crypto exchanges.
  • Monitor your systems for unusual behaviour that might indicate data exfiltration.

Remember, simply uninstalling the extension is not enough. Any secret that was present on the system during the infection period should be considered exposed.

Strengthening Your Defence: Best Practices for Developers

To reduce the risk of similar attacks in the future, adopt a more rigorous approach to extension management:

  • Audit your extensions regularly. Remove any that are not essential for your work.
  • Implement a strict installation policy. Only allow extensions from trusted publishers, and verify their legitimacy before installation.
  • Use a centralised registry to manage extensions across your team, ensuring only approved tools are used.
  • Separate sensitive operations from your main development environment. Use dedicated browser profiles for crypto transactions, and consider hardware wallets for signing transactions.
  • Keep your tools updated and be wary of extensions that request excessive permissions.

Protecting Your Servers and Infrastructure

For system administrators and hosting providers, this incident underscores the importance of robust server security. While VS Code extensions are a developer-side issue, the stolen credentials could be used to target your servers. Implementing proactive measures can help mitigate the damage:

  • Monitor server logs for unusual login attempts or IP addresses.
  • Enable two-factor authentication (2FA) for all administrative access.
  • Use a centralised security solution that can automatically block malicious IPs and manage fail2ban across multiple machines.

At ALMC.es, we understand the challenges of maintaining secure server environments. Our Abuse Shield service is designed to centralise your server protection, offering automatic blocking of malicious IPs, managed fail2ban across all your machines, and a shared reputation feed. This way, if one server detects a threat, all others are immediately protected.

Conclusion: Vigilance is Key

The discovery of these malicious VS Code extensions is a wake-up call for the developer community. It highlights the need for continuous vigilance and proactive security measures. By adopting stricter extension policies, separating sensitive tasks, and leveraging comprehensive security tools, you can significantly reduce your exposure to supply chain attacks. Remember, in the world of cybersecurity, trust is a vulnerability—verify before you install.

Related

  • Guard Your Code: The GhostSplice MCP Attack and How to Stay Safe
  • VMware vCenter CVE-2026-59310: Urgent Patch Guide for EU Admins
  • SharePoint Server Critical Flaw: Immediate Steps to Secure Your Farm
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Compliance Consulting (GDPR, ENS, ISO 27001)
Performance Optimization
Full Stack Web Development Laravel, Vue.js
Cloud Migration (AWS, Azure, Google Cloud)
Security Audits and Pentesting
Relacionados
  • Zapscape CVE-2026-64561: KVM Flaw Risks Host Security in Nested Virtualization
    Cybersecurity · 59 minutes ago
  • From SQL Injection to SYSTEM: How Oracle Java Became an Attacker's Tool
    Cybersecurity · 59 minutes ago
  • Coldcard Flaw: How Weak Seed Entropy Led to a $88M Bitcoin Heist
    Cybersecurity · 59 minutes ago
  • Cisco FMC zero-day exploited: what sysadmins must do now
    Cybersecurity · 59 minutes ago
  • Gitea Critical Flaw: Git Hooks Open Door to Server Takeover
    Cybersecurity · 59 minutes ago
  • GeoServer CVE-2024-36401: Act Fast to Shield Your Servers
    Cybersecurity · 1 hour ago
Servidores MCP Destacados
  • Metabase Server
    Database
  • NuGet Package README
    Development
  • Swagger/OpenAPI MCP Server
    Development
  • GitHub Explorer MCP
    Version Control
  • Yandex Browser Tabs
    Productivity
  • Travel MCP Server
    Productivity
  • Memory Pickle MCP
    Productivity
  • Amazon Nova Reel 1.1
    Cloud Service
  • MCP Data Analizer
    Productivity
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar