BTC $65,432.81 +1.25%
ETH $1,923.29 +2.82%
BNB $574.01 +0.86%
XRP $1.12 +2.21%
SOL $78.17 +2.11%
TRX $0.3258 -0.11%
DOGE $0.0725 +0.03%
ADA $0.1708 +3.51%
BCH $222.61 +4.48%
LINK $8.61 +2.14%
HYPE $62.65 +4.03%
AAVE $91.71 +2.44%
SUI $0.7663 +2.35%
XLM $0.1880 +0.67%
ZEC $549.65 +2.32%
BTC $65,432.81 +1.25%
ETH $1,923.29 +2.82%
BNB $574.01 +0.86%
XRP $1.12 +2.21%
SOL $78.17 +2.11%
TRX $0.3258 -0.11%
DOGE $0.0725 +0.03%
ADA $0.1708 +3.51%
BCH $222.61 +4.48%
LINK $8.61 +2.14%
HYPE $62.65 +4.03%
AAVE $91.71 +2.44%
SUI $0.7663 +2.35%
XLM $0.1880 +0.67%
ZEC $549.65 +2.32%

TRAE malicious Solidity extension exploits on-chain contracts to dynamically manage C2 configurations

2026-07-20 18:33:02
Collection

According to the security agency Slow Fog, the malicious TRAE IDE extension juannegro.solidity disguises itself as a Solidity plugin and acts as a cross-platform malware delivery mechanism. This extension automatically executes and establishes persistence after the IDE starts, and it also uses Ethereum smart contracts to store and retrieve dynamic C2 configurations, allowing attackers to update C2 endpoints and payloads without needing to re-release the extension.

Although the extension has been removed from Open VSX, it was still available through the TRAE marketplace as of July 18. Users who have installed it should immediately delete it and check their systems for compromise.

app_icon
ChainCatcher Building the Web3 world with innovations.