Login
Sign Up
Woofun AI reports that the malicious TRAE IDE extension 'juannegro.solidity' masquerades as a Solidity plugin while functioning as a cross-platform malware delivery mechanism. The extension automatically executes upon IDE startup and establishes persistence, utilizing Ethereum smart contracts to store and retrieve dynamic Command and Control configurations. This architecture allows attackers to update C2 endpoints and payloads without re-releasing the extension. Although removed from Open VSX, the extension remained available via the TRAE marketplace as of July 18. Users who installed the extension are advised to delete it immediately and audit their systems for compromise.