Skip to content

Security1 publisher2 min readPublished

SleepyDuck operator re-lists fake Solidity extensions on Open VSX hours after a takedown

Pluto Security says the SleepyDuck operator re-listed fake Solidity extensions on Open VSX within hours of a takedown, in a stage it calls EtherDuck. Each wave stayed up about 19 hours, long enough for a single install to leave persistent access that the takedown did not remove.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying SleepyDuck operator re-lists fake Solidity extensions on Open VSX hours after a takedown
Generated illustration

What happened

  • Four fake extensions posed as widely used Solidity and Hardhat development tools on Open VSX.
  • Their displayed download counts were inflated by more than 300,000 in a single day, lifting them above the genuine listings in search.
  • Windows victims received ScreenConnect after an elevation chain; macOS and Linux victims got a persistent shell that used an Ethereum smart contract as its C2 address book.
  • Payloads sat in an archive appended to a real 205 MB video file and were unpacked only at runtime.
  • A second wave came under new publisher identities with the same payloads, adding anti-sandbox and anti-debugger checks.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Download count and search rank could not separate the fake Solidity tools from the real ones in this campaign, so neither works as a vetting check for developer extensions.
  • decision A team relying on marketplace takedowns accepts about 19 hours of exposure per wave and keeps any payload installed in that time, so which extensions get installed has to be decided and enforced inside the organization.
  • precedent The operator has run three operations against Solidity developers in about a year with the same signature, so another wave under fresh publisher names is the expected case.

One install is all the operator needs. Pluto says a single installation established persistent remote access across major developer platforms [16]. The campaign carried payloads for Windows, macOS and Linux on both x64 and ARM64 [8]. Startup activation is among the techniques Pluto says the operator carried over from earlier waves [3].

Open VSX acted on each of Pluto's reports [10]. Two waves at about 19 hours each add up to roughly 38 hours of public listing [1], and Pluto says the speed of the response materially limited exposure [10]. Removal stopped new downloads [12]. It did not remove the Windows desktop access or the macOS and Linux shell from machines that already had them [12]. "The listings disappeared; the operator, tooling, and command infrastructure did not," Pluto wrote [14]. Pluto documents one return, the second wave after the first takedown [11]. It does not say what followed the second removal.

Pluto describes a Solidity developer's workstation as a control plane for repositories, build pipelines, cloud infrastructure, wallets and contract deployments [13]. The access it lists includes Git and SSH credentials, CI/CD tokens, package-publishing credentials, wallet keystores, private keys and contract deployment or upgrade authority [13]. From that position an operator can modify source, poison builds, publish compromised packages and authorize malicious on-chain activity [17]. For a team hit inside the window, every one of those credentials stays in scope after the listing is gone [12] [13].

This is a sustained operator. The first SleepyDuck extension, nearly a year before EtherDuck, used Ethereum for command-and-control; months later another fake Solidity extension delivered ScreenConnect through a similar chain [2]. The single-actor finding is Pluto's assessment, which it rates high confidence [3]. Its evidence is the reused duck ASCII art, persistence and anti-analysis behavior and Ethereum-based C2 configuration [3]. It adds that the spring and September 2026 waves used the same contract and byte-identical Go payloads [4]. Contracts, network infrastructure and implant code did change between operations [15].

Across all of it, the target and the delivery surface held: Solidity developers, reached through fake extensions on the same marketplace [3].

What to watch

  • A third EtherDuck wave on Open VSX under new publisher names, and whether it reuses the same payloads and Ethereum contract.
  • Any install counts or victim notifications from Open VSX or affected teams, since the inflated download figures cannot size the victim pool.
  • Any Open VSX change to how new publishers and download counts are handled after two waves gamed search ranking.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories