註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
加入 April 2018
410 正在關注    90.5K 粉絲
🚨 Beware of Solidity Pro: A Targeted Poisoning Attack on #Web3# Developers SlowMist Security Team has identified malicious activity in Solidity Pro, a #VSCode# extension targeting #Solidity#/Web3 developers. Historical versions under two publisher identities, helper-beeps and web3devtoolsx, were found to contain credential harvesting, remote payload execution, and remote VSIX update capabilities. Interestingly, these malicious capabilities disappeared from subsequent versions, while malicious source code and traces of the previous publisher remained in the repository. We traced the version history, publisher migration, and build artifacts, highlighting a key detection blind spot: Current-version-only detection may cause extensions with a malicious history to appear clean or low-risk again. This case highlights why #ExtensionSecurity# should go beyond a single file or version, incorporating version history, publisher changes, build provenance, and remote control planes. Read the full analysis 👇
顯示更多
0
4
44
15
轉發到社區