SlowMist: The TRAE IDE plugin market is seeing malicious extensions that can carry out attacks via on-chain contracts and steal crypto assets

robot
Abstract generation in progress
ME News, July 20 (UTC+8). SlowMist posted that in the plugin market of the AI code editor TRAE, there is a malicious extension juannegro.solidity. The extension disguises itself as a legitimate Solidity plugin; in fact, it is a cross-platform malware delivery tool. After installation, it can establish persistent presence on the device and accept remote control instructions, posing a threat to developers’ private keys, wallets, and on-chain assets. The attackers use Ethereum smart contracts to dynamically store and update the address of the remote control server. Without needing to republish the extension, they can switch attack endpoints at any time, making the activity more stealthy. Although the extension has already been removed from Open VSX, as of July 18 it could still be obtained via the TRAE plugin market. SlowMist reminded that users who have installed juannegro.solidity should uninstall it immediately and check whether their systems show signs of potential intrusion. (Source: Foresight News)
ETH0.05%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned