The juannegro.solidity plugin reportedly auto-executed on launch, established persistence and remained on the TRAE marketplace as of July 18 after removal from Open VSX.
A malicious TRAE IDE extension identified as juannegro.solidity posed as a Solidity plugin while functioning as a cross-platform malware dropper, according to SlowMist. The extension reportedly ran automatically when the IDE launched, set up persistence and used an Ethereum smart contract (self-executing blockchain code) to hold dynamic command-and-control, or C2, configuration. BlockBeats reported the findings on July 20, adding that the extension had been removed from Open VSX but was still available on the TRAE marketplace as of July 18. The case highlights how attackers can use blockchain-based infrastructure to make malicious control systems harder to disrupt.