律动BlockBeats|Jul 20, 2026 10:33
[SlowMist: Malicious Solidity Extension TRAE Exploits On-Chain Contracts for Dynamic C2 Configuration Management]
BlockBeats News, July 20 – According to security firm SlowMist, the malicious TRAE IDE extension *juannegro.solidity* disguises itself as a Solidity plugin and acts as a cross-platform malware dropper. This extension automatically executes and establishes persistence upon IDE startup. It leverages Ethereum smart contracts to store and retrieve dynamic C2 configurations, allowing attackers to update C2 endpoints and payloads without needing to republish the extension. Although the extension has been removed from Open VSX, it was still accessible via the TRAE marketplace as of July 18. Users who have installed it should immediately uninstall and check their systems for potential damage. [Original Link]
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink