Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Malicious IDE Extension Uses Solana for Data Theft

Malicious IDE Extension Uses Solana for Data Theft

Fake Developer Tool Exploits Trusted Environments

Kelly Cromley by Kelly Cromley
Mar 19, 2026
in Market News, News
Reading Time: 3 mins read
0
solana blockchain

Cybersecurity researchers at Bitdefender have identified a sophisticated malware campaign involving a malicious extension for the Windsurf integrated development environment (IDE). The extension, disguised as a legitimate R language support tool, was found to deploy a multi-stage NodeJS-based information stealer while leveraging the Solana blockchain as part of its payload delivery infrastructure.

The fraudulent extension closely imitates a legitimate tool known as REditorSupport, likely to mislead developers into installing it. Researchers indicated that the malware operated within the trusted extension ecosystem of the development environment, allowing it to evade immediate detection and persist even when endpoint protection tools flagged suspicious activity.

Multi-Stage Attack Targets Developer Systems

According to investigators, the attack begins when a user installs the malicious extension within the Windsurf IDE. Instead of relying on standalone executables, the malware executes within the NodeJS runtime environment associated with the IDE, granting it direct access to system resources and network functions.

Once activated, the extension decrypts an embedded payload that acts as a loader for additional malicious components. The initial stage focuses on profiling the system by collecting details such as usernames, environment variables, timezone settings, and locale information. Researchers explained that the malware specifically checks for indicators associated with Russian systems and terminates execution if such conditions are detected, suggesting an intentional effort to avoid targeting certain regions.

Following this profiling phase, the malware proceeds to retrieve additional payloads. Rather than using traditional command-and-control servers, it interacts with blockchain infrastructure by querying transactions on the Solana network. This decentralized approach makes detection and takedown efforts significantly more challenging.

Blockchain-Based Payload Delivery Mechanism

The malware reportedly sends requests to Solana’s public network interface to extract encoded data embedded within blockchain transaction metadata. These data fragments are then decoded and reconstructed into executable JavaScript code.

Security analysts noted that the payload consists of multiple layers, including base64 encoding and AES encryption, which are dynamically processed during runtime. This method allows the malware to remain concealed until execution, reducing the likelihood of detection during initial inspection.

Because the extension operates in a non-sandboxed NodeJS environment, it gains unrestricted access to the file system. This enables it to load native modules and deploy additional components without typical security constraints. The malware drops several compiled files into temporary system directories, including modules designed to extract sensitive data from Chromium-based browsers.

Credential Theft and Persistent Execution

The primary objective of the malware is data exfiltration. Researchers reported that it targets stored browser credentials, session cookies, and other sensitive information commonly found in Chromium-based applications. These data points are considered highly valuable, particularly in developer environments where access to APIs and privileged systems is common.

To ensure long-term persistence, the malware creates a hidden scheduled task using PowerShell. This task is configured to run at system startup with elevated privileges, enabling the malicious processes to continue operating even after the IDE is closed or the system is rebooted.

Additionally, the malware modifies and cleans registry entries to remove traces of its presence while maintaining its persistence mechanisms. It ultimately launches a NodeJS runtime process linked to its malicious scripts, ensuring continuous execution across system restarts.

Increasing Risks in Developer Ecosystems

The incident highlights a growing trend in which attackers exploit trusted development tools to distribute malware. Instead of relying on traditional delivery methods, threat actors are embedding malicious code within widely used software ecosystems, increasing the likelihood of successful infiltration.

Researchers emphasized that the deliberate exclusion of Russian systems suggests operational safeguards often associated with financially motivated cybercrime groups. By targeting developers, attackers gain access to high-value credentials, including API keys and privileged system access.

This case underscores the importance of verifying the authenticity of extensions and maintaining strict security practices within development environments. As blockchain technology becomes more integrated into cyber operations, its use in malware delivery is expected to present new challenges for cybersecurity defenses.

 

Previous Post

NEAR Intents Hits 20M Swaps, Signals Ecosystem Growth

Next Post

Tempo Blockchain Goes Live with AI Payment Protocol

Related Posts

polymarket

Polymarket Acquires Brahma in $1.2B Blockchain Deal

by Kelly Cromley
Mar 19, 2026
0

In a significant development within the cryptocurrency sector, Polymarket has acquired Brahma in a deal valued at $1.2 billion. The...

manadia

Manadia, Gametaverse DAO Advance AI-Blockchain Apps

by Kelly Cromley
Mar 19, 2026
0

Manadia and Gametaverse DAO have announced a strategic collaboration aimed at advancing the development of AI-native, on-chain applications. The partnership...

tempo

Tempo Blockchain Goes Live with AI Payment Protocol

by Kelly Cromley
Mar 19, 2026
0

Tempo, a payments-focused blockchain supported by Stripe and Paradigm, has officially launched its mainnet, introducing a new protocol designed to...

near protocol

NEAR Intents Hits 20M Swaps, Signals Ecosystem Growth

by Kelly Cromley
Mar 19, 2026
0

The NEAR Protocol ecosystem has recorded a significant milestone, with NEAR Intents surpassing 20 million swaps. This development is widely...

elliptic

Elliptic Expands Compliance Tools to Tempo Blockchain

by Kelly Cromley
Mar 19, 2026
0

Elliptic, a provider of digital asset decisioning solutions, has announced full blockchain coverage for Tempo, a payments-focused Layer-1 blockchain developed...

netx

NetX and GANA Insight Advance PayFi Infrastructure

by Kelly Cromley
Mar 19, 2026
0

NetX, a Web3 platform leveraging blockchain and artificial intelligence for payment solutions, has entered into a strategic partnership with GANA...

Next Post
tempo

Tempo Blockchain Goes Live with AI Payment Protocol

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

polymarket
Market News

Polymarket Acquires Brahma in $1.2B Blockchain Deal

by Kelly Cromley
Mar 19, 2026
manadia
Market News

Manadia, Gametaverse DAO Advance AI-Blockchain Apps

by Kelly Cromley
Mar 19, 2026
tempo
Market News

Tempo Blockchain Goes Live with AI Payment Protocol

by Kelly Cromley
Mar 19, 2026
solana blockchain
Market News

Malicious IDE Extension Uses Solana for Data Theft

by Kelly Cromley
Mar 19, 2026
near protocol
Market News

NEAR Intents Hits 20M Swaps, Signals Ecosystem Growth

by Kelly Cromley
Mar 19, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.