Rank#812
Security Findings
3Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in lang-resource-sync.js: chmod +x
lang-resource-sync.js
SleepyDuck Wakes Again: A Cross-Platform Open VSX Campaign Targeting Solidity Developer Workstations
MaliciousCuratorPluto Security documents EtherDuck, the latest wave of the SleepyDuck campaign, which distributed malicious Open VSX extensions impersonating popular Solidity/Hardhat tooling (via inflated download counts) to deliver cross-platform persistent remote-access malware hidden in an appended archive inside a valid 205 MB MP4, with an Ethereum smart contract serving as resilient C2 configuration. Advisory: https://pluto.security/blog/sleepyduck-malware-open-vsx-extensions