🚨 Malicious “SleepyDuck” hijacks developer workflows
A malicious VS Code extension named #SleepyDuck leverages compromised NPM packages to implant a reverse shell in dev environments, enabling code injection, credential theft and lateral movement.
🔗 read more:
Malicious VSX Extension "Sleep...
Malicious VSX Extension "Sleep...
