Skip to content
← Back to newsAI Extension Scam: $500,000 Crypto Heist Rocks Developer Community
Security

AI Extension Scam: $500,000 Crypto Heist Rocks Developer Community

By ToTo BugelmanNewcomer0 rep· 7/12/2025

 

A Russian blockchain developer recently lost $500,000 in cryptocurrency due to a sophisticated cyberattack involving a malicious AI extension for Visual Studio Code. The attackers exploited search ranking algorithms in the Open VSX registry to promote a fake "Solidity Language" extension, which then installed remote access tools and infostealers on the victim's system, highlighting a growing threat in the open-source ecosystem.

 

AI Extension Scam Leads to Half-Million Dollar Crypto Heist

In a concerning incident in June 2025, a Russian blockchain developer fell victim to a cunning cyberattack, resulting in the theft of approximately $500,000 in cryptocurrency. The breach originated from a seemingly innocuous Visual Studio Code-compatible extension for the Cursor AI integrated development environment.

 

The Deceptive "Solidity Language" Extension

The attack leveraged a malicious extension named "Solidity Language," which masqueraded as a legitimate tool for Solidity syntax highlighting. Despite the victim's stringent security practices, including using online malware detection services, the fake extension was inadvertently installed from the Open VSX registry.

  • The malicious extension had accumulated 54,000 downloads before its detection and removal.

  • It exploited the Open VSX registry's relevance-based ranking system, appearing higher in search results than the authentic extension due to a manipulated update date.

  • The fake extension contained no actual syntax highlighting functionality; instead, it served as a dropper for a multi-stage attack chain.

 

Sophisticated Infection Chain Unveiled

Upon installation, the malicious extension.js file initiated contact with a command and control (C2) server. The infection process unfolded as follows:

  1. Initial Script Download: A PowerShell script was downloaded from angelic[.]su, which checked for the presence of ScreenConnect remote management software.

  2. ScreenConnect Installation: If ScreenConnect was not detected, a secondary script downloaded and installed the legitimate remote access tool from lmfao[.]su, configured to communicate with the attackers' infrastructure at relay.lmfao[.]su.

  3. Payload Delivery: ScreenConnect was then used to install three Visual Basic Scripts (VBScripts) from relay[.]lmfao[.]su. These scripts retrieved further payloads, including the Quasar open-source backdoor and the PureLogs infostealer, from paste[.]ee.

  4. Steganography: The infostealer was hidden within an image uploaded to archive[.]org using steganography, and a VMDetector-based loader extracted it.

 

The extension.js file, stored at %userprofile%\.cursor\extensions\solidityai.solidity-1.0.9-universal\src\extension.js, contains code that requests a PowerShell script from the angelic[.]su web server and then runs it: Kaspersky

 

Broader Campaign and Impersonation Tactics

This incident is part of a larger campaign. Researchers identified related malicious packages, including "solsafe" in the npm repository and additional Visual Studio Code extensions like "solaibot," "among-eth," and "blankebesxstnion," all employing similar infection methodologies and C2 infrastructure.

 

Malicious script for VS Code extension (left) and Solidity Language extension (right): Kaspersky

 

After the initial malicious extension was removed, attackers swiftly published a new version under the identical "solidity" name, spoofing the legitimate developer's name by subtly replacing a lowercase "l" with an uppercase "I" to deceive users. This new version falsely claimed two million downloads to further inflate its perceived legitimacy.

 

Updated search results for solidity: Kaspersky

 

Lessons Learned and Recommendations

This attack underscores the evolving risks of supply-chain attacks in the open-source ecosystem. Even experienced developers can fall victim to well-concealed threats. Cybersecurity experts recommend:

  • Using commercial-grade endpoint protection.

  • Rigorously verifying extension authorship and scrutinizing unexpected behaviors.

  • Inspecting downloaded source code for anomalies.

  • Exercising extreme caution when installing extensions, especially those with artificially inflated download counts or suspicious update histories.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

AI Extension Scam: $500,000 Crypto Heist Rocks Developer Community | BlockzHub