Fake Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data
ID: 52c3510f-1326-50b1-b59b-9d66afbf79cb
STIX ID: report--52c3510f-1326-50b1-b59b-9d66afbf79cb
Feed Name: HackRead
Threat Score
A malicious extension disguised as an R language plugin for the Windsurf IDE has been discovered; it uses the Solana blockchain as a covert channel to retrieve encrypted JavaScript payloads, drops native modules (w.node and c_x64.node), establishes persistence via a PowerShell-created 'UpdateApp' scheduled task, and steals browser passwords and session cookies—targeting developers for high-value credentials while deliberately excluding systems with Russian timezones.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
