Malicious TRAE Extension juannegro.solidity Plants Onchain Backdoor with Dynamic C2 Configuration

ETH4.06%

According to SlowMist security team, a malicious extension named juannegro.solidity was found in the TRAE IDE marketplace, disguised as a legitimate Solidity plugin. Although removed from Open VSX, the extension remained accessible via TRAE marketplace as of July 18. SlowMist analysis shows the extension executes upon IDE startup, establishing persistence and using Ethereum smart contracts to store and retrieve dynamic C2 configurations, allowing attackers to update endpoints and payloads without republishing the extension.

Users who installed the extension are urged to remove it immediately and check for system compromise. The incident highlights extension marketplaces as initial infection vectors and blockchain infrastructure being exploited for dynamic C2 management.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments