Malicious TRAE Solidity Extension juannegro.solidity Uses Ethereum Smart Contracts to Manage C2 Configuration

ETH3.54%
According to Slow Mist, a malicious TRAE IDE extension named juannegro.solidity has been detected disguising itself as a Solidity plugin and serving as a cross-platform malware dropper. The extension automatically executes upon IDE startup, establishes persistence, and leverages Ethereum smart contracts to store and retrieve dynamic C2 configurations, allowing attackers to update C2 endpoints and payloads without redeploying the extension. Though removed from Open VSX, the extension remained available via the TRAE marketplace as of July 18. Affected users are advised to immediately uninstall and scan their systems for compromise.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments