Blockchain security firm SlowMist has released an IDE security alert warning developers that merely opening a malicious project folder can silently execute system-level commands. The attack requires no code execution — clicking "Open Folder" in a mainstream IDE is enough. Both Windows and macOS systems are vulnerable, making it a cross-platform threat that is already impacting real users.
SlowMist's team specifically called out the growing trend of Vibe Coding, where developers rely on AI-assisted IDEs like Cursor. These tools automatically scan files, load tasks, and interact with project settings. Attackers can craft malicious project folders that exploit these automatic behaviors — stealing data, installing malware, or draining cryptocurrency private keys. Multiple users of AI coding tools have reported actual losses, proving this is not a theoretical risk.
Why Opening a Folder Is Dangerous
Modern IDEs are designed for convenience: they auto-read configurations, execute extensions, and set up environments. That same convenience becomes a vulnerability when harmful scripts are embedded in project files. The IDE may parse or execute malicious content before the user even realizes a threat exists. Victims often discover the breach only after their crypto keys are stolen or their system is compromised.
Part of a Broader Trend in Crypto Security Threats
This IDE alert is not an isolated incident. Recent warnings from OKX Wallet and Phantom Wallet pointed to Solana signature phishing attacks, where victims are tricked into signing seemingly harmless transactions that transfer account ownership. A separate phishing wave targeting MetaMask users used fake 2FA alerts to trick people into entering recovery phrases on look-alike websites. All these attacks exploit user trust in routine actions rather than software vulnerabilities. Attackers design traps into normal behavior, waiting for victims to follow their usual workflow.
How Developers Can Protect Themselves
SlowMist advises developers to treat unknown project folders like unknown USB drives: never open untrusted repositories directly. Use virtual machines or sandbox environments for testing. When using AI-powered IDEs, verify the source of every project before opening. A simple habit of "verify before open" may be the strongest defense available right now.
YMYL Disclaimer: This article is for informational purposes only and does not provide financial, investment, or cybersecurity advice.

