MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Malicious VSX Extension “SleepyDuck” Leverages Ethereum for Command and Control – Cyberwarzone
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,577.00-0.15%
  • ethereumEthereum(ETH)$2,318.280.32%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.430.07%
  • binancecoinBNB(BNB)$637.730.35%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$86.441.27%
  • tronTRON(TRX)$0.323525-1.26%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.55%
  • dogecoinDogecoin(DOGE)$0.0984600.96%
Blockchain

Malicious VSX Extension “SleepyDuck” Leverages Ethereum for Command and Control – Cyberwarzone

Last updated: November 4, 2025 9:20 am
Published: 6 months ago
Share

A newly identified malicious extension, dubbed “SleepyDuck,” has been found in the Open VSX registry, employing the Ethereum blockchain to maintain its command and control (C2) infrastructure. The extension, initially distributed as a legitimate Solidity development tool, was updated to incorporate malicious functionalities.

The threat actor behind the extension, identified as juan-bianco.solidity-vlang (version 0.0.8), first published a benign version on October 31, 2025. A subsequent update on November 1, 2025, introduced remote access trojan capabilities. This malicious version gained traction after reaching a reported 14,000 downloads. Researchers from Secure Annex noted that the malware incorporates sandbox evasion techniques and uses an Ethereum contract to dynamically update its C2 server address, enhancing its resilience against takedown attempts.

The SleepyDuck malware initiates by connecting to an Ethereum Remote Procedure Call (RPC) provider. It then interacts with a specific smart contract, , to retrieve the address of its C2 server, reported as “sleepyduck[.]xyz”. The contract, created on October 31, 2025, was updated by the threat actor associated with address . Transaction data indicates the server address was changed from “localhost:8080” to “sleepyduck[.]xyz” through a series of four transactions.

Once connected, the malware establishes a polling loop, checking for new commands every 30 seconds. It is also designed to exfiltrate system information, including hostname, username, MAC address, and timezone, to the C2 server. If the primary C2 domain is compromised or taken offline, SleepyDuck is programmed with fallback mechanisms to query a predefined list of Ethereum RPC addresses to obtain updated server details from the contract. The extension can also receive new configurations and execute emergency commands across all compromised endpoints.

This discovery highlights a continuing trend of malicious extensions targeting software developers. Similar campaigns have been observed on both the Visual Studio Extension Marketplace and Open VSX, with past incidents resulting in significant cryptocurrency losses for victims. The article suggests that the download counts for SleepyDuck may have been artificially inflated to enhance its visibility and deceive developers.

In a related development, five other extensions published on the VS Code Extension Marketplace under the name “developmentinc” were found to contain malicious payloads. One such extension, themed around Pokémon, was observed downloading and executing a batch script miner from an external server. This script, after elevating its privileges and configuring exclusions in Microsoft Defender Antivirus, downloads and runs a Monero mining executable. The identified malicious extensions are no longer available for download.

Developers are strongly advised to exercise caution when downloading extensions, verifying publisher legitimacy and scrutinizing permissions. Microsoft has stated it is implementing periodic marketplace-wide scans to combat malware distribution. Information on removed extensions can be found on the RemovedPackages page on GitHub.

Read more on cyberwarzone.com

This news is powered by cyberwarzone.com cyberwarzone.com

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Satoshi May Hold A Lot of XRP: Ripple CTO
Antier Emerges as an Early Adopter of ERC-8004, Strengthening Trust in RWA Ecosystems | Weekly Voice
Cardano Price Prediction: ADA Plummets As Traders Back Viral ETH Layer 2 Dubbed The ‘Next SHIB’ – South Africa Today
BlockDAG’s $435M+ Value Era Redefines Market Focus as SHIB Holds Flat and Toncoin Falls 2.7% – Crypto Economy
Morgan Stanley Files for Bitcoin and Solana ETFs, Shiba Inu (SHIB) Price Erases Zero, Bollinger Shares XRP Warning — Crypto News Digest – U.Today

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article XRP News: Ripple’s $4 Billion Bet on Crypto Custody Deepens With Palisade Takeover
Next Article BingX Bridges TradFi and Web3 at Blockchain Life 2025, Celebrates Top Industry Recognition | Al Bawaba
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d