Odaily Planet Daily News: According to SlowMist monitoring, the malicious TRAE IDE extension juannegro.solidity disguises itself as a Solidity plugin and acts as a cross-platform malware dropper. The extension automatically executes upon IDE startup, establishes persistence, and uses Ethereum smart contracts to store and retrieve dynamic C2 configurations, allowing attackers to update C2 endpoints and payloads without needing to re-release the extension. Although the extension has been removed from Open VSX, as of July 18, it was still obtainable via the TRAE marketplace. Users who have installed it should immediately delete it and check their systems for compromise.
2026-07-20 10:33
Odaily星球日报讯 据慢雾监测,恶意 TRAE IDE 扩展 juannegro.solidity 伪装成 Solidity 插件,并作为跨平台恶意软件投递器。该扩展会在 IDE 启动后自动执行并建立持久化,还使用以太坊智能合约存储和获取动态 C2 配置,使攻击者无需重新发布扩展即可更新 C2 端点和载荷。该扩展虽已从 Open VSX 移除,但截至 7 月 18 日仍可通过 TRAE marketplace 获取,已安装用户应立即删除并检查系统是否受损。
