Malicious Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data
ID: 1bed4659-ea06-5543-bf98-7a9907c92ac1
STIX ID: report--1bed4659-ea06-5543-bf98-7a9907c92ac1
Feed Name: securityonline.info
Security researchers uncovered a targeted campaign distributing a malicious Windsurf IDE extension ('Windsurf Stealer') that uses the Solana blockchain for command-and-control. The malware remains dormant to evade detection, performs geographic checks to exclude certain regions, establishes persistence via a hidden PowerShell scheduled task and registry manipulation, and launches a Node.js-based stealer that leverages native.node DLLs to harvest Chromium browser passwords, cookies, and developer secrets — posing a high-risk supply-chain threat to developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
