Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor

Three IoliteLabs VSCode extensions (solidity-macos, solidity-windows, solidity-linux) containing obfuscated backdoors targeting Solidity and Web3 developers across Windows, macOS, and Linux. The backdoors download remote payloads and establish persistence mechanisms on infected systems.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Solidity and Web3 developers using the affected IoliteLabs VSCode extensions on Windows, macOS, and Linux
Ecosystems
Attack vectors
Affected entities
  • solidity-macosIoliteLabs VSCode extension
  • solidity-windowsIoliteLabs VSCode extension
  • solidity-linuxIoliteLabs VSCode extension

A supply chain attack has been discovered targeting Solidity and Web3 developers through three malicious VSCode extensions distributed under the IoliteLabs name. The affected extensions—solidity-macos, solidity-windows, and solidity-linux—embed obfuscated backdoor code designed to function across all major operating systems. The backdoors download remote payloads and establish persistence mechanisms on compromised machines. StepSecurity identified and disclosed the attack and indicated that a full technical analysis with indicators of compromise (IOCs) and remediation guidance would be published separately.

Indicators of compromise

Packages
  • solidity-macos
  • solidity-windows
  • solidity-linux

Remediation

  • Immediately uninstall solidity-macos, solidity-windows, and solidity-linux VSCode extensions from all systems
  • Scan systems for persistence mechanisms and remote payloads left by the backdoor
  • Review system logs and network traffic for suspicious outbound connections from the backdoor
  • Reset credentials and API keys used on affected systems
  • Update VSCode and all extensions to the latest versions from official sources
  • Monitor for indicators of compromise (IOCs) published by StepSecurity

Sources

  1. Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor · StepSecurity

Cite this entry

"Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed April 2, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-mac-1fkfap

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers

    A coordinated 8-month supply chain attack compromised 15 malicious JetBrains plugins on the official JetBrains Marketplace, stealing AI API keys from approximately 70,000 developers. The credential-stealing code exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to an attacker-controlled server in Beijing, which remained operational at the time of disclosure.

    OtherCompromised packageMalicious maintainer
  2. activecritical

    The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

    TeamPCP conducted a multi-ecosystem supply chain compromise targeting the @antv package and associated development infrastructure. The attack leveraged GitHub, NPM, and VSCode to steal credentials and establish persistence mechanisms.

    TeamPCPnpmOtherAccount takeoverCompromised packageMalicious maintainer
  3. containedcritical

    Malicious code in intercom-php (Packagist)

    The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials and can propagate to NPM packages using discovered credentials.

    Mini Shai HuludTeamPCPNuGetCompromised packageMalicious maintainer
  4. containedcritical

    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

    Three RubyGems (git_credential_manager, Dendreo, and fastlane) were compromised to deliver a persistent backdoor named SleeperGem. The malicious packages fetch a second stage payload from a Forgejo C2 server, bypass CI checks, and install a persistent daemon on developer machines.

    RubyGemsCompromised packageMalicious maintainer