logo

Windsurf IDE Extension Drops Malware via Solana Blockchain

ID: 4ee49506-2b61-5c1d-827a-ffd8828842db

STIX ID: report--4ee49506-2b61-5c1d-827a-ffd8828842db

Feed Name: Bitdefender Labs

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-04-27

Author: Raul Vasile BUCUR

...
...

**Executive summary:** Bitdefender discovered a malicious Windsurf IDE extension (reditorsupporter.r-vscode-2.8.8-universal) that infects developer environments with a multi-stage NodeJS credential stealer; the extension fetches AES-encrypted payload fragments from Solana blockchain transactions, dynamically executes them, drops native .node modules to extract Chromium credentials and cookies, and establishes persistence via a hidden PowerShell scheduled task named UpdateApp, while deliberately avoiding Russian systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.