A fake Solidity addon was found on the VS Code marketplace.The malicious extension was downloaded 1.7 million times in one day.The extension executes the attack fully in memory, leaving no evidence on the disk.It uses PowerShell for execution and recognizes VMs to protect against reverse engineering.