BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious Solidity Extension SleepyDuck Malware Targets Developers

SleepyDuck Malware Found in Open VSX Registry Using Ethereum Smart Contract for Remote Control; Additional Malicious Cryptocurrency Mining Extensions Discovered on VS Code Marketplace

  • A new malicious extension called SleepyDuck was found in the Open VSX registry.
  • The extension initially appeared harmless but added Malware after 14,000 downloads.
  • SleepyDuck uses an Ethereum smart contract for remote control and evades detection.
  • Five more malicious extensions with cryptocurrency mining capabilities were discovered on the VS Code Marketplace.
  • Users are warned to download extensions only from trusted sources, with Microsoft implementing regular security scans.

Cybersecurity researchers have revealed a harmful extension called SleepyDuck in the Open VSX registry that operates as a remote access trojan. The extension, named juan-bianco.solidity-vlang, was first published on October 31, 2025, without malicious features but was updated on November 1 to include malware after reaching 14,000 downloads.

- Advertisement -

According to Secure Annex researcher John Tuckner, the malware uses techniques to avoid Sandbox detection and connects to an Ethereum smart contract to update its command and control (C2) server address if needed. The contract address linked to the malware is 0xDAfb81732db454DA238e9cFC9A9Fe5fb8e34c465.

The malware activates when users open a code editor window or select a file with the “.sol” extension used in Ethereum smart contract programming. It searches for the fastest Ethereum Remote Procedure Call (RPC) provider to connect and communicates with a server at “sleepyduck[.]xyz.” Every 30 seconds, it polls the server for new instructions to execute on the infected device.

SleepyDuck also gathers information such as the computer’s hostname, username, MAC address, and timezone, sending these details back to the attacker. If the main domain is taken down, the malware can retrieve new server details from a preset list of Ethereum RPC addresses to maintain control.

Separately, Secure Annex uncovered five additional malicious extensions in the Visual Studio Code Marketplace published by a user named “developmentinc.” One of these carries a Pokémon-themed library that downloads and runs a cryptocurrency miner for Monero. This miner runs with administrator privileges, disables Windows Defender scanning across drives, and executes mining software from an external server (“mock1[.]su”).

- Advertisement -

The five extensions identified are:
– developmentinc.cfx-lua-vs
– developmentinc.pokemon
– developmentinc.torizon-vs
– developmentinc.minecraftsnippets
– developmentinc.kombai-vs

All of these extensions have since been removed from the marketplace.

Users are urged to verify the credibility of extension publishers before downloading. Microsoft announced in June that it will conduct periodic, comprehensive scans of its extension marketplace to reduce malware risks. A list of removed extensions is publicly available on the RemovedPackages page on GitHub.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

U.S. Blocks Anthropic’s Top AI Models Over Security Fears

The U.S. government ordered Anthropic to suspend foreign access to its advanced AI models,...

Critical Splunk Vulnerability Allows Unauthenticated RCE

Splunk has patched a critical vulnerability, CVE-2026-20253, rated 9.8 on the CVSS scale, allowing...

AI Agent Bills Operator $6.5k After Wild AWS Spree

An AI agent deployed by an operator named JertLinc autonomously spun up five powerful...

Bitcoin ETF Inflows Spark Hope After 2026 Price Lows

Bitcoin has plunged to 2026 lows of under $60,000, down 50% from its October...

Investors Bet on Onchain Credit Infrastructure Over DeFi

Morpho Labs raises $175M from investors like Paradigm, aiming to become a foundational credit...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading