The SlowMist security team has identified a malicious extension, juannegro.solidity, in the TRAE IDE marketplace, posing as a legitimate Solidity plugin. This extension acts as a cross-platform malware dropper, automatically executing upon IDE startup and using an Ethereum smart contract to manage dynamic C2 configurations. Despite its removal from Open VSX, it remains available on the TRAE marketplace as of July 18. SlowMist warns that this extension allows attackers to update C2 endpoints and deliver malicious payloads without republishing. Users are advised to uninstall the extension and check for system compromises. This incident underscores the risk of extension marketplaces as infection vectors and the potential misuse of blockchain infrastructure for C2 management.
Malicious TRAE Extension Uses On-chain Backdoor for Dynamic C2 Updates
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
