慢雾:TRAE恶意Solidity扩展利用链上合约动态管理C2配置
2026-07-20 10:33
Odaily Planet Daily News: According to SlowMist's monitoring, the malicious TRAE IDE extension juannegro.solidity masquerades as a Solidity plugin and acts as a cross-platform malware dropper. The extension executes automatically upon IDE startup, establishes persistence, and uses Ethereum smart contracts to store and retrieve dynamic C2 configurations, allowing attackers to update C2 endpoints and payloads without re-releasing the extension. Although the extension has been removed from Open VSX, it remains available via the TRAE marketplace as of July 18. Users who have installed it should delete it immediately and check their systems for compromise.
