Malicious TRAE IDE extension used Ethereum smart contract for C2, SlowMist says

The juannegro.solidity plugin reportedly auto-executed on launch, established persistence and remained on the TRAE marketplace as of July 18 after removal from Open VSX.

ETH

Summary

A malicious TRAE IDE extension identified as juannegro.solidity posed as a Solidity plugin while functioning as a cross-platform malware dropper, according to SlowMist. The extension reportedly ran automatically when the IDE launched, set up persistence and used an Ethereum smart contract (self-executing blockchain code) to hold dynamic command-and-control, or C2, configuration. BlockBeats reported the findings on July 20, adding that the extension had been removed from Open VSX but was still available on the TRAE marketplace as of July 18. The case highlights how attackers can use blockchain-based infrastructure to make malicious control systems harder to disrupt.

Terms & Concepts
  • Solidity: Programming language for Ethereum smart contracts.
  • smart contract: Self-executing blockchain code.
  • C2: Command-and-control system used by malware.