


Perceptive Security
SOC/SIEM Consultancy

Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor
Published:
27 maart 2026 om 20:41:51
Alert date:
27 maart 2026 om 21:04:38
Source:
stepsecurity.io
Supply Chain & Dependencies, Ransomware & Malware, Security Tools
Cybercriminals deployed malicious Visual Studio Code extensions under the IoliteLabs brand targeting Solidity developers across Windows, macOS, and Linux platforms. These extensions contain backdoor functionality designed to compromise developer environments. The attack represents a supply chain threat specifically targeting blockchain and smart contract developers. The malicious extensions were distributed through VSCode marketplace channels. This campaign demonstrates sophisticated targeting of cryptocurrency and DeFi development communities through developer tool compromise.
Technical details
Mitigation steps:
Affected products:
Visual Studio Code
VSCode Extensions
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
