SleepyDuck is a remote access trojan (RAT) distributed via a malicious Open VSX extension masquerading as a Solidity extension, identified as juan-bianco.solidity-vlang. Reporting states the extension was initially published as a benign package on 2025-10-31 and updated on 2025-11-01 with malicious functionality after reaching roughly 14,000 downloads; total downloads were reported as exceeding 53,000. The malware targets developers using VS Code-style editors, including Solidity developers, and activates when the editor starts, when a new editor window opens, when a .sol file is opened or selected, or when a compile command runs. SleepyDuck disguises execution through a fake webpack.init() mechanism and creates a lock file during initial activation. Its capabilities include sandbox evasion, collection and exfiltration of host information such as hostname, username, MAC address, and timezone, establishment of a command-execution sandbox, and polling for commands every 30 seconds. The primary C2 domain reported is sleepyduck[.]xyz. A notable resilience feature is its use of Ethereum smart contracts / blockchain infrastructure to obtain or update C2 details, including fallback to predefined Ethereum RPC providers if the primary domain is disrupted. Reported associated blockchain infrastructure includes contract address 0xDAfb81732db454DA238e9cFC9A9Fe5fb8e34c465, which was used to store updated server details and support emergency commands to infected endpoints. The malware has been linked in reporting to malicious extension activity tracked by Secure Annex and to broader malicious extension campaigns affecting Open VSX and the VS Code ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
the extension in question, juan-bianco.solidity-vlang (version 0.0.7), was first published on October 31, 2025, as a completely benign library that was subsequently updated to version 0.0.8 on November 1 to include new malicious capabilities after reaching 14,000 downloads.
In the event the domain is seized or taken down, the malware has built-in fallback controls to reach out to a predefined list of Ethereum RPC addresses to extract the contract information that can hold the server details.
initialize contact with a remote server at "sleepyduck[.]xyz" ... and kicks off a polling loop that checks for new commands to be executed on the host every 30 seconds.
the malware has built-in fallback controls to reach out to a predefined list of Ethereum RPC addresses to extract the contract information that can hold the server details. What's more, the extension is equipped to reach a new configuration from the contract address to set a new server
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SleepyDuck is a remote access trojan (RAT) distributed via IDE extensions, which uses Ethereum smart contracts for persistence and command and control.
Supply-chain delivered RAT distributed via a trojanized Open VSX VSCode extension; collects host/user/system metadata and uses Ethereum smart contracts for resilient blockchain-based C2 to receive instructions even if primary infrastructure is taken down.
Remote Access Trojan distributed via malicious VSCode extensions, using both traditional C2 and Ethereum smart contracts for backup command and control. Targets developers using Solidity extensions.
A remote access trojan (RAT) distributed as an IDE extension, notable for using Ethereum smart contracts for persistence mechanisms.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.