The SlowMist security team has identified a malicious extension, juannegro.solidity, in the TRAE IDE marketplace, posing as a legitimate Solidity plugin. This extension acts as a cross-platform malware dropper, automatically executing upon IDE startup and using an Ethereum smart contract to manage dynamic C2 configurations. Despite its removal from Open VSX, it remains available on the TRAE marketplace as of July 18. SlowMist warns that this extension allows attackers to update C2 endpoints and deliver malicious payloads without republishing. Users are advised to uninstall the extension and check for system compromises. This incident underscores the risk of extension marketplaces as infection vectors and the potential misuse of blockchain infrastructure for C2 management.