PANews reported on April 21 that according to a post forwarded by SlowMist Technology Chief Information Security Officer 23pds from X platform user @mrdotparasyte, a suspicious VSCode plug-in named JuanFranBlanco.solidit-vscode was discovered. The download volume of this plug-in is suspected to be obtained through improper means, the plug-in information is also suspicious, and the "solidit" in the plug-in identifier is obviously a typo. This plug-in has been in existence for two or three days, and it is not clear how many developers have accidentally been "hit". At present, supply chain attacks against developers are becoming more and more rampant, especially VSCode plug-ins and npm packages that have not been officially reviewed, which have become the hardest hit areas for such attacks. Hereby remind all developers to be vigilant and carefully identify when installing third-party plug-ins or packages.
SlowMist CISO: Beware of the suspicious VSCode plugin "JuanFranBlanco.solidit-vscode"
- 2025-05-12
Layer0 blockchain infrastructure platform Openverse Network completes $11 million in strategic financing
- 2025-05-12
The U.S. Treasury Department will hold a closed-door roundtable on stablecoins on May 15
- 2025-05-12
HashKey Group Announces the Official Launch of HashKey Global MENA and Obtains UAE Virtual Asset Service Provider (VASP) License
- 2025-05-12
Analysis: Ethereum has recently achieved a growth of more than 60%, mainly due to Vitalik's simplified vision and technical upgrades
- 2025-05-12
TokenInsight released a rating report for BGB, with an A rating
- 2025-05-12
The “reciprocal tariff war” has entered the third stage, crypto assets have rebounded across the board, and BTC may quickly break through the previous high (05.05~05.11)