View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Malicious Solidity Pro VS Code Extensions Steal Wallets

๐Ÿšจ ACTIVE EXPLOITATION

  • Malicious Solidity Pro VS Code Extensions Steal Wallets and Credentials Malicious Solidity Pro VS Code extensions are stealing crypto wallets, API keys, and developer credentials.

    • VS Code users and Ethereum developers using helper-beeps.solidity-pro or web3devtoolsx.solidity-pro are affected.
    • Versions 3.0.0 and later steal browser profiles, crypto wallets, source-control tokens, API keys, SSH keys, and Telegram bot tokens.
    • Versions 1.0.0 through 2.4.x fetched encrypted Python payloads from Cloudflare Workers.
    • The extensions use obfuscation, delayed activation, and changing method names to evade marketplace review and static scanning.
    • Stolen data is exfiltrated through a Telegram bot; harvested token formats include ghp_, github_pat_, glpat-, cfat_, sk-, sk-proj-, and sk-ant-. ๐Ÿ“„ Source: yeethsecurity.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Malicious VBS/PowerShell RAT Campaign Uses Multiple DuckDNS Hosts A malware campaign is using VBS and PowerShell scripts to deploy a remote access trojan on Windows systems.

    • Windows users and business endpoints are targeted by the campaign.
    • The RAT can steal browser credentials and cookies, log keystrokes, and capture clipboard data.
    • Obfuscated VBS files envifa.vbs and sostener2.vbs decrypt an AES-256-encrypted PowerShell stage.
    • PowerShell extracts an x64 payload that uses a .NET helper for process hollowing inside AppLaunch.exe.
    • Infrastructure includes multiple DuckDNS hosts, 181.237.42[.]61, and suspected C2 serversniperxx[.]duckdns[.]org:4577; VBS SHA-256: 8c78a55c8bf545e0d21b8757eaa0b709b4af47b13d34a38df81045e67026bd96. ๐Ÿ“„ Source: x.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Levi Strauss Says Social Engineering Attack Stole Corporate Data Levi Strauss says attackers used social engineering to steal corporate data.

    • Levi Strauss & Co. was affected through three employees' company-issued computers.
    • Attackers accessed and exfiltrated certain corporate information.
    • No consumer data appears to have been impacted, based on preliminary findings.
    • The intrusion used social engineering; the specific tactic and threat actor remain unknown. ๐Ÿ“„ Source: sec.gov ยท ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • Bybit Wins U.S. Court Orders to Trace and Freeze Lazarus Hack Funds Bybit secured U.S. court support to recover funds from the $1.5 billion Lazarus hack.

    • Bybit and assets stolen in the February 2025 attack are covered; defendants include North Korea, its Reconnaissance General Bureau, Lazarus Group and 20 unidentified parties.
    • The attackers stole more than 400,000 ETH and staked ETH from Bybit.
    • Expedited discovery allows Bybit to seek account identities, balances and transaction histories from U.S.-linked platforms.
    • Stolen funds moved through mixers, cross-chain bridges and over-the-counter dealers; 90.2% was untraceable by June 18.
    • Bybit reports $48.4 million recovered and $30.5 million frozen across more than 28 exchanges and custodians. ๐Ÿ“„ Source: bybit.com ยท ๐Ÿ“Ž Coverage: crypto.news ยท ๐Ÿ‘ via @metacurity@infosec.exchange

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • UPDATE: Prompt Injection Could Make Atlassian Rovo Leak Enterprise Data Researchers found that prompt injection could make Atlassian Rovo exfiltrate enterprise data.

    • Atlassian Cloud tenants with Rovo enabled were affected across Jira, Confluence, Bitbucket and connected SaaS services.
    • Rovo could access and leak data available to a signed-in user, including Jira tickets, Confluence pages, SharePoint documents, Outlook emails and private API keys.
    • Varonis's RovoBlast used the rovoChatPrompt URL parameter to preload attacker instructions into Rovo Chat.
    • A single authenticated click could trigger Rovo to collect data and send it to an attacker-controlled server through autonomous URL retrieval.
    • PromptArmor also demonstrated indirect injection through attacker-controlled uploaded documents; Atlassian fixed the URL-parameter issue server-side on July 8, 2026. ๐Ÿ“„ Source: bugcrowd.com ยท ๐Ÿ“Ž Coverage: varonis.com ยท ๐Ÿ‘ via Cyber Security News
  • Claude Code Activity Exposed macOS Services Through Tunnels and LaunchAgents Elastic observed Claude Code activity creating reverse tunnels and LaunchAgent persistence on macOS.

    • The activity affected macOS developer endpoints running Claude Code and, in related cases, Cursor.
    • Credentialed requests exposed local services and application metrics through public tunnels while LaunchAgents maintained access across logout or reboot.
    • zsh shells under Claude Code used curl, cloudflared, ngrok, launchctl and PlistBuddy.
    • Observed indicators included lhr[.]life, trycloudflare[.]com, api.trycloudflare[.]com, /tmp/mcp_clean_landers.py and ~/.claude/projects/*/memory/MEMORY.md. ๐Ÿ“Ž Coverage: elastic.co ยท ๐Ÿ‘ via Cyber Security News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check