MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: New ‘SleepyDuck’ Malware in Open VSX Marketplace Allow Attackers to Control Windows Systems Remotely
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$67,147.000.24%
  • ethereumEthereum(ETH)$1,974.370.91%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.380.92%
  • binancecoinBNB(BNB)$616.332.50%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$80.74-0.81%
  • tronTRON(TRX)$0.2788031.55%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.051.23%
  • dogecoinDogecoin(DOGE)$0.0926411.72%
Blockchain

New ‘SleepyDuck’ Malware in Open VSX Marketplace Allow Attackers to Control Windows Systems Remotely

Last updated: November 5, 2025 3:05 am
Published: 3 months ago
Share

A sophisticated remote access trojan named SleepyDuck has infiltrated the Open VSX IDE extension marketplace, targeting developers using code editors like Cursor and Windsurf.

The malware disguised itself as a legitimate Solidity extension under the identifier juan-bianco.solidity-vlang, exploiting name squatting techniques to deceive unsuspecting users.

Initially published on October 31st as version 0.0.7, the extension appeared harmless until it was maliciously updated to version 0.0.8 on November 1st, gaining new capabilities after accumulating 14,000 downloads.

The extension masquerades as a development tool for Solidity programming, a language commonly used in blockchain and smart contract development.

Attackers leveraged this popular category to maximize their victim pool among cryptocurrency developers and blockchain engineers.

What makes this threat particularly dangerous is its ability to establish persistent remote access to infected Windows systems while maintaining stealth through various evasion techniques.

Secure Annex analysts identified the malware’s unique persistence mechanism that utilizes Ethereum blockchain contracts to maintain command and control infrastructure.

This innovative approach allows attackers to update their control server addresses even if the primary domain is seized or taken offline.

The malware communicates with sleepyduck[.]xyz as its default command and control server, employing a 30-second polling interval to receive instructions from threat actors.

The infection begins when the extension activates upon opening a new code editor window or selecting a .sol file.

The malware retrieves critical machine information including hostname, username, MAC address, and timezone data, which helps it evade sandbox analysis environments commonly used by security researchers.

SleepyDuck demonstrates advanced persistence through blockchain technology, representing a concerning evolution in malware infrastructure.

The threat maintains resilience by storing fallback configuration data in Ethereum contract address 0xDAfb81732db454DA238e9cFC9A9Fe5fb8e34c465.

When connectivity to the primary command server fails, the malware queries this immutable blockchain contract to retrieve updated server addresses, polling intervals, and even emergency commands for all infected endpoints.

The malware’s activation function creates a lock file to ensure single execution, then invokes a deceptive webpack.init() function that initializes the malicious payload.

During initialization, it identifies the fastest Ethereum RPC provider from a hardcoded list, establishes a command execution sandbox through vm.createContext(sandbox), and begins its polling loop to await attacker instructions.

This architecture grants attackers complete remote control over compromised systems while maintaining operational security through decentralized infrastructure that cannot be easily dismantled.

Read more on Cyber Security News

This news is powered by Cyber Security News Cyber Security News

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Top 7 Cryptos With Explosive Growth Potential This Year – Crypto Economy
How tokenization’s ‘superpowers’ could transform US stock access
Sathya Sai Baba a great emissary of peace, love: Vice-President – Mangalorean.com
Naver Financial To Acquire Dunamu In $10+ Billion All-Stock Deal
Cloudflare Suffers Outage: But Blockchain Kept Working — CZ

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Bitcoin Crashes To $99,750 as $250 Billion Wiped From Crypto Market News ETHNews
Next Article Trump Admin Explains CZ Pardon Amid Shutdown Woes
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d