{"id":78439,"date":"2025-07-13T10:58:51","date_gmt":"2025-07-13T07:58:51","guid":{"rendered":"https:\/\/gulftech-news.com\/en\/?p=78439"},"modified":"2025-07-13T11:00:51","modified_gmt":"2025-07-13T08:00:51","slug":"kaspersky-uncovers-500k-crypto-heist-through-malicious-packages","status":"publish","type":"post","link":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/","title":{"rendered":"Kaspersky uncovers $500K crypto heist through malicious packages"},"content":{"rendered":"\n<p><strong><a href=\"https:\/\/www.googleadservices.com\/pagead\/aclk?sa=L&amp;ai=DChsSEwi378TerbmOAxV_hv0FHSnQJ-4YACICCAEQABoCd2Y&amp;ae=2&amp;aspm=1&amp;co=1&amp;ase=2&amp;gclid=Cj0KCQjwss3DBhC3ARIsALdgYxNnSTJ7rPH-KigiS5M6ULStrViCNvICD5Vvf_3a6oP-LdEqXMdLpocaAiujEALw_wcB&amp;ohost=www.google.com&amp;cid=CAESVuD2W3JlrV8zwq32VZ4kQISF35fdsGnJoub3T0VYs9lyLsX1NnhcMbb0WpKRtB-Lsb196cq_s9MSiWjOZx_sSW27v3fqXIa7gR5rV3e-dqxGXczWMP7P&amp;category=acrcp_v1_43&amp;sig=AOD64_3tXPMw-68CVGVXzQNhIjN5809xUA&amp;q&amp;nis=4&amp;adurl&amp;ved=2ahUKEwi_5sDerbmOAxX9U6QEHc4VLtIQ0Qx6BAgcEAE\">Kaspersky <\/a>GReAT (Global Research and Analysis Team) experts have discovered open-source packages that download the Quasar backdoor and a stealer designed to exfiltrate cryptocurrency. The malicious packages are intended for the Cursor AI development environment, which is based on Visual Studio Code \u2014 a tool used for AI-assisted coding.<\/strong><\/p>\n\n\n\n<p>The malicious open-source packages are extensions hosted in the Open VSX repository that claim to provide support for the Solidity programming language. However, in practice, they download and execute malicious code on users&#8217; devices.<\/p>\n\n\n\n<p>During an incident response, a blockchain developer from Russia reached out to Kaspersky after installing one of these fake extensions on his computer, which allowed attackers to steal approximately $500,000 worth of crypto assets.<\/p>\n\n\n\n<p>The threat actor behind these packages managed to deceive the developer by making the malicious package rank higher than the legitimate one. The attacker achieved this by artificially inflating the malicious package\u2019s downloads count to 54,000.<\/p>\n\n\n\n<p><em>Search results for the query \u201csolidity\u201d: the malicious extension (highlighted in red) and the legitimate one (highlighted in green).<\/em><\/p>\n\n\n\n<p>After installation, the victim gained no actual functionality from the extension. Instead, malicious ScreenConnect software was installed on the computer, granting threat actors remote access to the infected device.<\/p>\n\n\n\n<p> Using this access, they deployed the open-source Quasar backdoor along with a stealer that collects data from browsers, email clients, and crypto wallets. With these tools, the threat actors were able to obtain the developer\u2019s wallet seed phrases and subsequently steal cryptocurrency from the accounts.<\/p>\n\n\n\n<p>After the malicious extension downloaded by the developer was discovered and removed from the repository, the threat actor republished it and artificially inflated its installation count to a higher number \u2013 2 million, compared to 61,000 for the legitimate package. The extension was removed from the platform following a request from Kaspersky.<\/p>\n\n\n\n<p><em>\u201cSpotting compromised open-source packages with the naked eye is becoming increasingly<\/em> <em>difficult. Threat actors are using increasingly creative tactics to deceive potential victims, even developers who have a strong understanding of cybersecurity risks \u2014 particularly those working in the blockchain development field. <\/em><\/p>\n\n\n\n<p><em>As we expect adversaries to continue targeting developers, it is recommended that even experienced IT professionals deploy dedicated security solutions to safeguard sensitive data and prevent financial losses,\u201d<\/em> commented Georgy Kucherin, Security Researcher with Kaspersky\u2019s Global Research and Analysis Team.<\/p>\n\n\n\n<p>The threat actor behind the attack published not only malicious Solidity extensions but also another NPM package, <em>solsafe<\/em>, which also downloads ScreenConnect. A few months earlier, three additional malicious Visual Studio Code extensions were released \u2014 <em>solaibot<\/em>, <em>among-eth<\/em>, and <em>blankebesxstnion<\/em> \u2014 all of them have already been removed from the repository.<\/p>\n\n\n\n<p>To stay safe, Kaspersky recommends:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use a<a href=\"https:\/\/www.kaspersky.com\/open-source-feed\"> solution<\/a> for monitoring the used open-source components in order to detect the threats that might be hidden inside.<\/li>\n\n\n\n<li>If you suspect that a threat actor may have gained access to your company\u2019s infrastructure, we recommend using the<a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/compromise-assessment?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder____\"> Kaspersky Compromise Assessment<\/a> service to uncover any past or ongoing attacks.<\/li>\n\n\n\n<li>Verify package maintainers: check the credibility of the maintainer or organization behind the package. Look for consistent version history, documentation, and an active issue tracker.<\/li>\n\n\n\n<li>Stay informed on emerging threats: subscribe to security bulletins and advisories related to the open-source ecosystem. The earlier you know about a threat, the faster you can respond.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky GReAT (Global Research and Analysis Team) experts have discovered open-source packages that download the Quasar backdoor and a stealer designed to exfiltrate cryptocurrency. The malicious packages are intended for the Cursor AI development environment, which is based on Visual Studio Code \u2014 a tool used for AI-assisted coding. The malicious open-source packages are extensions &hellip;<\/p>\n","protected":false},"author":2,"featured_media":78440,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1088],"class_list":["post-78439","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-kaspersky-4"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Kaspersky uncovers $500K crypto heist through malicious packages - Gulf Tech News<\/title>\n<meta name=\"description\" content=\"Kaspersky uncovers $500K crypto heist through malicious packages\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kaspersky uncovers $500K crypto heist through malicious packages - Gulf Tech News\" \/>\n<meta property=\"og:description\" content=\"Kaspersky uncovers $500K crypto heist through malicious packages\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/\" \/>\n<meta property=\"og:site_name\" content=\"Gulf Tech News\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-13T07:58:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-13T08:00:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"bessan helmi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"bessan helmi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/\",\"url\":\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/\",\"name\":\"Kaspersky uncovers $500K crypto heist through malicious packages - Gulf Tech News\",\"isPartOf\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516\",\"datePublished\":\"2025-07-13T07:58:51+00:00\",\"dateModified\":\"2025-07-13T08:00:51+00:00\",\"author\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\"},\"description\":\"Kaspersky uncovers $500K crypto heist through malicious packages\",\"breadcrumb\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#primaryimage\",\"url\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516\",\"contentUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516\",\"width\":1200,\"height\":600,\"caption\":\"Kaspersky uncovers $500K crypto heist through malicious packages\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/gulftech-news.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kaspersky uncovers $500K crypto heist through malicious packages\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\",\"url\":\"https:\/\/gulftech-news.com\/en\/\",\"name\":\"Gulf Tech News\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/gulftech-news.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\",\"name\":\"bessan helmi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"caption\":\"bessan helmi\"},\"url\":\"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kaspersky uncovers $500K crypto heist through malicious packages - Gulf Tech News","description":"Kaspersky uncovers $500K crypto heist through malicious packages","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/","og_locale":"en_US","og_type":"article","og_title":"Kaspersky uncovers $500K crypto heist through malicious packages - Gulf Tech News","og_description":"Kaspersky uncovers $500K crypto heist through malicious packages","og_url":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/","og_site_name":"Gulf Tech News","article_published_time":"2025-07-13T07:58:51+00:00","article_modified_time":"2025-07-13T08:00:51+00:00","og_image":[{"width":1200,"height":600,"url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516","type":"image\/jpeg"}],"author":"bessan helmi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"bessan helmi","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/","url":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/","name":"Kaspersky uncovers $500K crypto heist through malicious packages - Gulf Tech News","isPartOf":{"@id":"https:\/\/gulftech-news.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#primaryimage"},"image":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#primaryimage"},"thumbnailUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516","datePublished":"2025-07-13T07:58:51+00:00","dateModified":"2025-07-13T08:00:51+00:00","author":{"@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c"},"description":"Kaspersky uncovers $500K crypto heist through malicious packages","breadcrumb":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#primaryimage","url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516","contentUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/07\/Solidity-featured-AI-generaged-image.jpg?v=1752393516","width":1200,"height":600,"caption":"Kaspersky uncovers $500K crypto heist through malicious packages"},{"@type":"BreadcrumbList","@id":"https:\/\/gulftech-news.com\/en\/2025\/07\/13\/kaspersky-uncovers-500k-crypto-heist-through-malicious-packages\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gulftech-news.com\/en\/"},{"@type":"ListItem","position":2,"name":"Kaspersky uncovers $500K crypto heist through malicious packages"}]},{"@type":"WebSite","@id":"https:\/\/gulftech-news.com\/en\/#website","url":"https:\/\/gulftech-news.com\/en\/","name":"Gulf Tech News","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gulftech-news.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c","name":"bessan helmi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","caption":"bessan helmi"},"url":"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/"}]}},"_links":{"self":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/78439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/comments?post=78439"}],"version-history":[{"count":2,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/78439\/revisions"}],"predecessor-version":[{"id":78442,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/78439\/revisions\/78442"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media\/78440"}],"wp:attachment":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media?parent=78439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/categories?post=78439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/tags?post=78439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}