Windsurf IDE Extension Drops Malware via Solana Blockchain
ID: 4ee49506-2b61-5c1d-827a-ffd8828842db
STIX ID: report--4ee49506-2b61-5c1d-827a-ffd8828842db
Feed Name: Bitdefender Labs
**Executive summary:** Bitdefender discovered a malicious Windsurf IDE extension (reditorsupporter.r-vscode-2.8.8-universal) that infects developer environments with a multi-stage NodeJS credential stealer; the extension fetches AES-encrypted payload fragments from Solana blockchain transactions, dynamically executes them, drops native .node modules to extract Chromium credentials and cookies, and establishes persistence via a hidden PowerShell scheduled task named UpdateApp, while deliberately avoiding Russian systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
