The fake extension, “contractshark.solidity-lang,” displayed professional branding, a polished description, and boasted over 54,000 downloads, enough to appear trustworthy. Once installed, it quietly accessed Cole’s .env file, extracted his private key, and transmitted it to an attacker. The hacker then…
Read full article