Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Malicious IDE Extension Uses Solana for Data Theft

Malicious IDE Extension Uses Solana for Data Theft

Fake Developer Tool Exploits Trusted Environments

Kelly Cromley by Kelly Cromley
Mar 19, 2026
in Market News, News
Reading Time: 3 mins read
0
solana blockchain

Cybersecurity researchers at Bitdefender have identified a sophisticated malware campaign involving a malicious extension for the Windsurf integrated development environment (IDE). The extension, disguised as a legitimate R language support tool, was found to deploy a multi-stage NodeJS-based information stealer while leveraging the Solana blockchain as part of its payload delivery infrastructure.

The fraudulent extension closely imitates a legitimate tool known as REditorSupport, likely to mislead developers into installing it. Researchers indicated that the malware operated within the trusted extension ecosystem of the development environment, allowing it to evade immediate detection and persist even when endpoint protection tools flagged suspicious activity.

Multi-Stage Attack Targets Developer Systems

According to investigators, the attack begins when a user installs the malicious extension within the Windsurf IDE. Instead of relying on standalone executables, the malware executes within the NodeJS runtime environment associated with the IDE, granting it direct access to system resources and network functions.

Once activated, the extension decrypts an embedded payload that acts as a loader for additional malicious components. The initial stage focuses on profiling the system by collecting details such as usernames, environment variables, timezone settings, and locale information. Researchers explained that the malware specifically checks for indicators associated with Russian systems and terminates execution if such conditions are detected, suggesting an intentional effort to avoid targeting certain regions.

Following this profiling phase, the malware proceeds to retrieve additional payloads. Rather than using traditional command-and-control servers, it interacts with blockchain infrastructure by querying transactions on the Solana network. This decentralized approach makes detection and takedown efforts significantly more challenging.

Blockchain-Based Payload Delivery Mechanism

The malware reportedly sends requests to Solana’s public network interface to extract encoded data embedded within blockchain transaction metadata. These data fragments are then decoded and reconstructed into executable JavaScript code.

Security analysts noted that the payload consists of multiple layers, including base64 encoding and AES encryption, which are dynamically processed during runtime. This method allows the malware to remain concealed until execution, reducing the likelihood of detection during initial inspection.

Because the extension operates in a non-sandboxed NodeJS environment, it gains unrestricted access to the file system. This enables it to load native modules and deploy additional components without typical security constraints. The malware drops several compiled files into temporary system directories, including modules designed to extract sensitive data from Chromium-based browsers.

Credential Theft and Persistent Execution

The primary objective of the malware is data exfiltration. Researchers reported that it targets stored browser credentials, session cookies, and other sensitive information commonly found in Chromium-based applications. These data points are considered highly valuable, particularly in developer environments where access to APIs and privileged systems is common.

To ensure long-term persistence, the malware creates a hidden scheduled task using PowerShell. This task is configured to run at system startup with elevated privileges, enabling the malicious processes to continue operating even after the IDE is closed or the system is rebooted.

Additionally, the malware modifies and cleans registry entries to remove traces of its presence while maintaining its persistence mechanisms. It ultimately launches a NodeJS runtime process linked to its malicious scripts, ensuring continuous execution across system restarts.

Increasing Risks in Developer Ecosystems

The incident highlights a growing trend in which attackers exploit trusted development tools to distribute malware. Instead of relying on traditional delivery methods, threat actors are embedding malicious code within widely used software ecosystems, increasing the likelihood of successful infiltration.

Researchers emphasized that the deliberate exclusion of Russian systems suggests operational safeguards often associated with financially motivated cybercrime groups. By targeting developers, attackers gain access to high-value credentials, including API keys and privileged system access.

This case underscores the importance of verifying the authenticity of extensions and maintaining strict security practices within development environments. As blockchain technology becomes more integrated into cyber operations, its use in malware delivery is expected to present new challenges for cybersecurity defenses.

 

Previous Post

NEAR Intents Hits 20M Swaps, Signals Ecosystem Growth

Next Post

Tempo Blockchain Goes Live with AI Payment Protocol

Related Posts

Crypto.com

Crypto.com Unveils Tokenized Stocks as RWA Market Surpasses $43 Billion

by Kelly Cromley
Jun 18, 2026
0

Crypto.com has launched a Tokenized Stocks feature within its mobile application, expanding access to U.S. equities through blockchain-based infrastructure. The...

India

India’s NPCI Launches Open-Source Drunix to Accelerate Enterprise Blockchain Adoption

by Kelly Cromley
Jun 18, 2026
0

The National Payments Corporation of India (NPCI) has introduced Drunix, a new open-source, enterprise-grade blockchain platform designed to support organizations...

Binance Wallet

Binance Unveils Web3 Wallet API for Multi-Chain Trading Access

by Kelly Cromley
Jun 17, 2026
0

Binance has introduced its Web3 Wallet API, a new infrastructure solution designed to provide developers, institutions, and advanced traders with...

Adapt ANP3

Adapt and Trikon Partner to Simplify Web3 With AI Agents

by Kelly Cromley
Jun 17, 2026
0

AdaptHF, an agentic network focused on decentralized artificial intelligence solutions, has announced a strategic partnership with Trikon, a decentralized platform...

Ripple XRP Ledger

XRPL 3.2.0 Upgrade Boosts Security, Speed, and Scalability

by Kelly Cromley
Jun 17, 2026
0

The XRP Ledger (XRPL) has entered a significant new stage of development following the release of XRPL 3.2.0, a major...

decibel

DecibelTrade Launches Onchain DEX for Stocks, ETFs and Crypto

by Kelly Cromley
Jun 17, 2026
0

DecibelTrade officially launched its fully on-chain decentralized exchange (DEX), introducing a platform designed to give users direct control over trading...

Next Post
tempo

Tempo Blockchain Goes Live with AI Payment Protocol

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

Crypto.com
Market News

Crypto.com Unveils Tokenized Stocks as RWA Market Surpasses $43 Billion

by Kelly Cromley
Jun 18, 2026
India
Market News

India’s NPCI Launches Open-Source Drunix to Accelerate Enterprise Blockchain Adoption

by Kelly Cromley
Jun 18, 2026
Binance Wallet
Market News

Binance Unveils Web3 Wallet API for Multi-Chain Trading Access

by Kelly Cromley
Jun 17, 2026
Adapt ANP3
Market News

Adapt and Trikon Partner to Simplify Web3 With AI Agents

by Kelly Cromley
Jun 17, 2026
Ripple XRP Ledger
Market News

XRPL 3.2.0 Upgrade Boosts Security, Speed, and Scalability

by Kelly Cromley
Jun 17, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.