0.9.3

    Solidity

    Solidity and Hardhat support by the Hardhat team

    Rank#811
    Publisher Nomic-ETHRegistry openvsx347,432Last scanned Sep 26, 2026, 05:11 PMRegistry

    Security Findings

    3

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Download-and-execute in lang-resource-sync.js: chmod +x

    lang-resource-sync.js

    Dangerous security bypass flags

    SuspiciousScanner

    Gatekeeper bypass in content: xattr -c

    SleepyDuck Wakes Again: A Cross-Platform Open VSX Campaign Targeting Solidity Developer Workstations

    MaliciousCurator

    Pluto Security documents EtherDuck, the latest wave of the SleepyDuck campaign, which distributed malicious Open VSX extensions impersonating popular Solidity/Hardhat tooling (via inflated download counts) to deliver cross-platform persistent remote-access malware hidden in an appended archive inside a valid 205 MB MP4, with an Ethereum smart contract serving as resilient C2 configuration. Advisory: https://pluto.security/blog/sleepyduck-malware-open-vsx-extensions