According to Slow Mist, a malicious extension named juannegro.solidity has been discovered in the TRAE AI code editor's plugin marketplace. The extension masquerades as a legitimate Solidity plugin but functions as a cross-platform malware delivery tool. Once installed, it establishes persistent presence on a device and accepts remote control commands, threatening developers' private keys, wallets, and on-chain assets.
The attackers exploit Ethereum smart contracts to dynamically update remote control server addresses, allowing them to switch attack endpoints without republishing the extension. While the extension has been removed from Open VSX, it remained accessible through the TRAE plugin marketplace as of July 18. Slow Mist urged users who have installed juannegro.solidity to uninstall it immediately and check their systems for potential intrusions.