Fake Solidity VSCode extension on Open VSX backdoors developers
ID: aa07e465-1f36-502b-9439-88bb6d63c08b
STIX ID: report--aa07e465-1f36-502b-9439-88bb6d63c08b
Feed Name: Bleeping Computer
A malicious remote access trojan called SleepyDuck was distributed via a fake 'juan-bianco.solidity-vlang' extension on the Open VSX registry; initially benign at submission, it received a malicious update and has been downloaded over 53,000 times. The malware activates on editor startup or when compiling Solidity, collects host identifiers (hostname, username, MAC, timezone), and establishes a resilient C2 by reading configuration (including server addresses and polling intervals) from an Ethereum smart contract, enabling updates even if the primary C2 is taken down.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
