

My software is somewhat standard. Plain Debian or Plain Fedora.
I did not install any VPN software and used a generic wireguard file in network manager. I had chatted with the VPN owner who seemed nice. All VPNs involve a certain level of trust and the hack may not be related.
The router firmware is official manufacturer firmware, SHA256 verified, that probably does have unpatched CVE vulnerabilities because they are slow with firmware updates. I’ve considered moving the firmware to OpenWrt to reduce attack surface since CVEs are patched more quickly with OpenWrt.
I did not clean the keyboard at all. I do not believe I triggered keyboard shortcuts. I didn’t spray anything.
The second (bad) laptop works fine after a reboot. I do not have the second hard drive plugged into it anymore and am not playing the FLAC files. Methodically testing again seems risky as the infection seemed to start in the second laptop, but not persist after reboot and unplugging the first hard drive. I’m concerned about damaging the Fedora laptop by testing.
I update via cron, everything was up to date in terms of packages.
VLC was in flatpak, it would have had to escape a sandbox to get out. VLC was recently updated.
I’m not that knowledgeable compared to someone who is a skilled hacker or developer. I’ve taken programming courses. I’m not that ignorant on these topics, but I’m not a real developer.
I was working on open source software that would have made it harder to do network correlation attacks. Probably no one would have cared, because I’m no one, but I am don’t know for sure. Everything about this seems implausible to me.
It’s a decent idea, but there’s risks of doing things that way.
The Debian laptop has a damaged keyboard no matter what I do, this includes when I am using the bios, and this includes when I plug in a USB keyboard, which also seems to always have caps locked/shift held down with this laptop and certain keys not working. That suggests a damaged keyboard controller right?
The Fedora laptop is currently working. When I plugged in the Debian hard drive in an enclosure via USB, the keyboard suddenly stopped working normally, with caps lock held down and shift held down, and then I unplugged it and rebooted.
I can’t test the Debian laptop. I already reflashed the bios and the keyboard doesn’t work in that, so I know experimenting with a new OS isn’t going to change anything. I also tried another OS on it and had the same problem. The Debian laptop is damaged. I have no idea where, I suspect it’s a keyboard controller or motherboard firmware, but I don’t know.
If I test the Fedora laptop, I risk transferring firmware malware over that may survive a reboot, unlike last time. It could be the bios and chipset is just resistant to this attack and it will never persist. It could also be that I just noticed it quickly and it wasn’t able to gain permanence, but would have done so with time.
To test this involves a risk of damaging motherboard or chip firmware that I can’t simply reset. I could test this again by plugging in the Debian hard drive into the working Fedora laptop, playing the Lana del Rey song again, and just seeing what happens. But what if this breaks the Fedora laptop too?