PANews reported on April 21 that according to a post forwarded by SlowMist Technology Chief Information Security Officer 23pds from X platform user @mrdotparasyte, a suspicious VSCode plug-in named JuanFranBlanco.solidit-vscode was discovered. The download volume of this plug-in is suspected to be obtained through improper means, the plug-in information is also suspicious, and the "solidit" in the plug-in identifier is obviously a typo. This plug-in has been in existence for two or three days, and it is not clear how many developers have accidentally been "hit". At present, supply chain attacks against developers are becoming more and more rampant, especially VSCode plug-ins and npm packages that have not been officially reviewed, which have become the hardest hit areas for such attacks. Hereby remind all developers to be vigilant and carefully identify when installing third-party plug-ins or packages.
SlowMist CISO: Beware of the suspicious VSCode plugin "JuanFranBlanco.solidit-vscode"
- 2025-05-11
USDT0 is now integrated into Hyperliquid
- 2025-05-10
Gate.io and Inter Milan goalkeeper Sommer join forces to set a new benchmark for crypto trading security
- 2025-05-10
Optimism: Isthmus hard fork activated, bringing key features from Ethereum’s Pectra upgrade to OP Stack and Superchain
- 2025-05-10
ZachXBT: Law enforcement mistakenly detained former Yuga Labs security researcher in 2022 BAYC NFT theft
- 2025-05-09
Inferno Drainer malware makes a comeback, stealing $9 million from crypto wallets in the past 6 months
- 2025-05-09
Removing OP_Return: What impact does it have on the Bitcoin ecosystem?