Malicious Windsurf IDE Extension Uses Solana to Deliver Credential-Stealing Malware

Summary
Bitdefender researchers describe a fake Windsurf R-language extension that retrieves encrypted JavaScript from Solana, deploys Chromium data-stealing modules, and persists through a hidden Windows scheduled task.
Key points
- The malicious extension, named reditorsupporter.r-vscode-2.8.8-universal, impersonated R-language support and ran inside the Windsurf IDE.
- It retrieved encoded JavaScript from Solana transactions via the blockchain's JSON-RPC interface instead of using a traditional command-and-control server.
- The malware deployed native Node.js modules to extract saved passwords, cookies, session tokens, and other Chromium browser data.
- A system-profiling check caused the malware to stop on systems identified as Russian.
- PowerShell created a hidden, startup-triggered scheduled task named UpdateApp to maintain persistence across reboots.
- Bitdefender EDR detections on a corporate workstation prompted the investigation.
Article Details
- Attack Vectors
- A malicious R development extension named reditorsupporter.r-vscode-2.8.8-universal was installed in Windsurf IDE, using a name similar to the legitimate REditorSupport extension.
- The extension decrypted an embedded JavaScript loader and retrieved additional encoded payload fragments from Solana transaction metadata.
- Execution inside the non-sandboxed NodeJS extension environment allowed filesystem access and loading of native credential-stealing modules.
- Native modules extracted saved credentials, cookies, session tokens, and encrypted secrets from Chromium-based browsers.
- PowerShell created an UpdateApp scheduled task to relaunch the malware at startup through a bundled NodeJS runtime.
- Defensive Notes
- Bitdefender EDR detections involving windsurf.exe initiated the investigation; malicious extension logic nevertheless persisted despite detections tied to the main application process.
- Manual inspection of the .windsurf extension directory identified the suspicious package and its embedded encrypted loader.
- The article identifies the absence of strict sandbox isolation in the NodeJS extension environment as enabling unrestricted filesystem access and native-module loading.
- The article states that retrieving payloads from the Solana blockchain makes takedown efforts significantly harder than using traditional command-and-control servers.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe extension concealed its loader in an encrypted embedded payload and retrieved base64-encoded JavaScript containing AES-encrypted components.T1033 · System Owner/User DiscoveryThe decrypted loader collected the current username during initial system profiling.T1036.005 · Match Legitimate Resource Name or LocationThe malicious reditorsupporter.r-vscode-2.8.8-universal extension used a name similar to the legitimate REditorSupport extension to confuse potential victims.T1053.005 · Scheduled TaskPowerShell created a scheduled task named UpdateApp that ran at startup with highest privileges and relaunched the malware.T1059.001 · PowerShellThe malware invoked PowerShell to configure persistence, interact with the registry, and launch the bundled NodeJS runtime.T1059.007 · JavaScriptThe malicious extension executed a multistage JavaScript payload within the IDE's NodeJS environment.T1105 · Ingress Tool TransferThe malware queried Solana blockchain transactions through JSON-RPC and retrieved encoded JavaScript payload fragments from transaction metadata.T1112 · Modify RegistryThe persistence script removed entries matching specific execution patterns from HKCU:\Software\Microsoft\Windows\CurrentVersion\Run.T1129 · Shared ModulesThe malware loaded native DLL components as .node add-ons through NodeJS to extract browser data.T1140 · Deobfuscate/Decode Files or InformationThe loader decrypted the embedded payload and decoded remotely retrieved JavaScript fragments before reconstructing the malicious runtime.T1204.002 · Malicious FileA user installed the malicious R development extension inside Windsurf IDE, triggering the infection.T1539 · Steal Web Session CookieThe native modules retrieved browser cookies and session tokens.T1555.003 · Credentials from Web BrowsersNative stealer modules accessed Chromium browser profiles and extracted saved credentials and encrypted browser secrets.T1564.003 · Hidden WindowThe PowerShell persistence component hid its console window using Win32 API calls through Add-Type.T1614.001 · System Language DiscoveryThe loader checked language markers, locale, timezone, and UTC offset for Russian-system indicators and stopped execution when its criteria matched.
People
Vendors
Products
Bitdefender EDRThe investigation began after Bitdefender EDR generated multiple detections involving a windsurf.exe on a corporate workstation.Chromiumblockchain transactions, executes it using NodeJS runtime primitives, drops compiled add-ons to extract Chromium data, all the while establishing persistence with the help of a hidden PowerShell scheduled task.Node.jsBitdefender researchers have discovered a malicious Windsurf IDE (integrated development environment) extension that deploys a multi-stage NodeJS stealer by using the Solana blockchain as the payload infrastructure.REditorSupportThere’s an official, legitimate extension named REditorSupport, which is likely why the attacker used a very similar name to confuse potential victims.Visual Studio CodeThe extension, disguised as an R language support extension for Visual Studio Code, retrieves encrypted JavaScript from blockchain transactions, executes it using NodeJS runtime primitives, drops compiled add-ons toWindsurf IDEWindsurf IDE Extension Drops Malware via Solana Blockchain