TRAE Malware Extension Uses On-Chain Contracts for Dynamic C2 Management
2026-07-20 18:33

Woofun AI reports that the malicious TRAE IDE extension 'juannegro.solidity' masquerades as a Solidity plugin while functioning as a cross-platform malware delivery mechanism. The extension automatically executes upon IDE startup and establishes persistence, utilizing Ethereum smart contracts to store and retrieve dynamic Command and Control configurations. This architecture allows attackers to update C2 endpoints and payloads without re-releasing the extension. Although removed from Open VSX, the extension remained available via the TRAE marketplace as of July 18. Users who installed the extension are advised to delete it immediately and audit their systems for compromise.

Disclaimer: Views are the author's own and do not represent the platform. Do not reproduce without permission. Content is for reference only, not investment advice. Trade at your own risk.
Tags:
TRAE
juannegro.solidity
Open VSX
Slow Fog
Ethereum
Share:
back