A sophisticated remote access malware called SleepyDuck has infiltrated the Open VSX IDE extension market , targeting developers using code editors such as Cursor and Windsurf . The malware disguised itself as a legitimate Solidity extension with the identifier juan-bianco.solidity-vlang , exploiting name-spoofing techniques to trick unsuspecting users.
See also: Self-replicating worm detected in Visual Studio Code

Originally released on October 31 as version 0.0.7 , it appeared harmless until it was maliciously updated to version 0.0.8 on November 1, gaining new features after accumulating 14,000 downloads. The extension is presented as a development tool for Solidity programming, a language commonly used in blockchain and smart contract development. Attackers exploited this popular category to maximize their victims among cryptocurrency developers and blockchain engineers.
What makes this threat particularly dangerous is its ability to establish persistent remote access to infected Windows systems while maintaining its stealth through various evasion techniques. Secure Annex identified the malware’s unique persistence mechanism that uses Ethereum blockchain to maintain its command and control infrastructure. This innovative approach allows attackers to update the addresses of their control servers even if the primary domain is hijacked or down.
See also: Open VSX: Addresses Token leaks and malicious extensions

The malware communicates with sleepyduck[.]xyz as its default command and control server, using a 30-second polling interval to receive instructions from attackers. Infection begins when the extension is triggered when a new code editor window is opened or a .sol. The malware retrieves critical machine information, such as the computer name, username, MAC address, and time zone data, which helps it evade sandbox analysis environments commonly used by security researchers.
SleepyDuck demonstrates advanced persistence via blockchain technology, representing a worrying development in malware infrastructure. The threat maintains resilience by storing backup configuration data at the Ethereum contract address 0xDAfb81732db454DA238e9cFC9A9Fe5fb8e34c465. When connectivity to the master command server fails, the malware queries this immutable blockchain contract to retrieve updated server addresses, audit intervals, and even emergency commands for all infected endpoints.
See also: Over 100 VS Code extensions expose developers

The malware’s activation function creates a lock file to ensure a single execution, and then calls a deceptive webpack.init() that initializes the malicious payload. During initialization, it finds the fastest Ethereum RPC provider from a hardcoded list, creates a command execution sandbox via vm.createContext(sandbox) , and starts its control loop to await instructions from attackers. This architecture gives attackers complete remote control of compromised systems while maintaining operational security through a decentralized infrastructure that cannot be easily dismantled.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
