Malicious Windsurf IDE Extension Uses Solana to Deliver Credential-Stealing Malware

· Original article ↗

Summary

Bitdefender researchers describe a fake Windsurf R-language extension that retrieves encrypted JavaScript from Solana, deploys Chromium data-stealing modules, and persists through a hidden Windows scheduled task.

Key points

  • The malicious extension, named reditorsupporter.r-vscode-2.8.8-universal, impersonated R-language support and ran inside the Windsurf IDE.
  • It retrieved encoded JavaScript from Solana transactions via the blockchain's JSON-RPC interface instead of using a traditional command-and-control server.
  • The malware deployed native Node.js modules to extract saved passwords, cookies, session tokens, and other Chromium browser data.
  • A system-profiling check caused the malware to stop on systems identified as Russian.
  • PowerShell created a hidden, startup-triggered scheduled task named UpdateApp to maintain persistence across reboots.
  • Bitdefender EDR detections on a corporate workstation prompted the investigation.

Article Details

Attack Vectors
  • A malicious R development extension named reditorsupporter.r-vscode-2.8.8-universal was installed in Windsurf IDE, using a name similar to the legitimate REditorSupport extension.
  • The extension decrypted an embedded JavaScript loader and retrieved additional encoded payload fragments from Solana transaction metadata.
  • Execution inside the non-sandboxed NodeJS extension environment allowed filesystem access and loading of native credential-stealing modules.
  • Native modules extracted saved credentials, cookies, session tokens, and encrypted secrets from Chromium-based browsers.
  • PowerShell created an UpdateApp scheduled task to relaunch the malware at startup through a bundled NodeJS runtime.
Defensive Notes
  • Bitdefender EDR detections involving windsurf.exe initiated the investigation; malicious extension logic nevertheless persisted despite detections tied to the main application process.
  • Manual inspection of the .windsurf extension directory identified the suspicious package and its embedded encrypted loader.
  • The article identifies the absence of strict sandbox isolation in the NodeJS extension environment as enabling unrestricted filesystem access and native-module loading.
  • The article states that retrieving payloads from the Solana blockchain makes takedown efforts significantly harder than using traditional command-and-control servers.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe extension concealed its loader in an encrypted embedded payload and retrieved base64-encoded JavaScript containing AES-encrypted components.T1033 · System Owner/User DiscoveryThe decrypted loader collected the current username during initial system profiling.T1036.005 · Match Legitimate Resource Name or LocationThe malicious reditorsupporter.r-vscode-2.8.8-universal extension used a name similar to the legitimate REditorSupport extension to confuse potential victims.T1053.005 · Scheduled TaskPowerShell created a scheduled task named UpdateApp that ran at startup with highest privileges and relaunched the malware.T1059.001 · PowerShellThe malware invoked PowerShell to configure persistence, interact with the registry, and launch the bundled NodeJS runtime.T1059.007 · JavaScriptThe malicious extension executed a multistage JavaScript payload within the IDE's NodeJS environment.T1105 · Ingress Tool TransferThe malware queried Solana blockchain transactions through JSON-RPC and retrieved encoded JavaScript payload fragments from transaction metadata.T1112 · Modify RegistryThe persistence script removed entries matching specific execution patterns from HKCU:\Software\Microsoft\Windows\CurrentVersion\Run.T1129 · Shared ModulesThe malware loaded native DLL components as .node add-ons through NodeJS to extract browser data.T1140 · Deobfuscate/Decode Files or InformationThe loader decrypted the embedded payload and decoded remotely retrieved JavaScript fragments before reconstructing the malicious runtime.T1204.002 · Malicious FileA user installed the malicious R development extension inside Windsurf IDE, triggering the infection.T1539 · Steal Web Session CookieThe native modules retrieved browser cookies and session tokens.T1555.003 · Credentials from Web BrowsersNative stealer modules accessed Chromium browser profiles and extracted saved credentials and encrypted browser secrets.T1564.003 · Hidden WindowThe PowerShell persistence component hid its console window using Win32 API calls through Add-Type.T1614.001 · System Language DiscoveryThe loader checked language markers, locale, timezone, and UTC offset for Russian-system indicators and stopped execution when its criteria matched.

People

Vendors

Products

Countries

Related Articles