TRAE IDE Hosts Malicious Extension Using Ethereum Smart Contracts for Remote Control
2026-07-20 16:35

Woofun AI reports that the TRAE AI code editor plugin market hosts a malicious extension named juannegro.solidity, which operates as cross-platform malware. The tool establishes persistent device access and accepts remote commands, targeting private keys and wallets. Attackers utilize Ethereum smart contracts to dynamically store and update remote control server addresses, enabling endpoint switching without new releases to enhance stealth. Although removed from Open VSX, the extension remains available in TRAE as of July 18. Manwu advises immediate uninstallation and system checks for affected users.

Disclaimer: Views are the author's own and do not represent the platform. Do not reproduce without permission. Content is for reference only, not investment advice. Trade at your own risk.
Tags:
慢雾
TRAE
juannegro.solidity
Solidity
Open VSX
以太坊
Share:
back