Login
Sign Up
Woofun AI reports that the TRAE AI code editor plugin market hosts a malicious extension named juannegro.solidity, which operates as cross-platform malware. The tool establishes persistent device access and accepts remote commands, targeting private keys and wallets. Attackers utilize Ethereum smart contracts to dynamically store and update remote control server addresses, enabling endpoint switching without new releases to enhance stealth. Although removed from Open VSX, the extension remains available in TRAE as of July 18. Manwu advises immediate uninstallation and system checks for affected users.