early warning by the slow fog security team: malicious poisoning of the vscode plugin “solidity pro”
Wu stated that it had been informed that the slow fog security team had warned of malicious poisoning in a vscode plugin for developer Solidity/Web3 “Solidity pro”. The analysis showed that the plugin had been found to contain malicious functions such as document theft, remote payload execution and remote vsix updates in historical versions in the status of publishers of the Helper-beeps and Web3devtoolsx. Despite the removal of these malicious functions from subsequent versions, there are still traces of malicious source code and former publishers in the code repository. The slow fog indicated that the detection of only the current version of the security blind zone could make the plugin with a malicious history look “clean” or low risk, emphasizing that the plugin security review should cover the multiple dimensions of the version's history, the publisher's change, the construction of traceability and remote control。
