TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Bitdefender Labs

Windsurf IDE Extension Drops Malware via Solana Blockchain

Raul Vasile BUCUR · 2026-03-18 · Read original ↗

ATT&CK techniques detected

2 predictions
T1176.002IDE Extensions
87%
"windsurf ide extension drops malware via solana blockchain bitdefender researchers have discovered a malicious windsurf ide ( integrated development environment ) extension that deploys a multi - stage nodejs stealer by using the solana blockchain as the payload infrastructure."
T1176Software Extensions
36%
"windsurf ide extension drops malware via solana blockchain bitdefender researchers have discovered a malicious windsurf ide ( integrated development environment ) extension that deploys a multi - stage nodejs stealer by using the solana blockchain as the payload infrastructure."

Summary

Bitdefender researchers have discovered a malicious Windsurf IDE (integrated development environment) extension that deploys a multi-stage NodeJS stealer by using the Solana blockchain as the payload infrastructure.