SlowMist said a malicious extension, juannegro.solidity, was found in the TRAE plugin marketplace for the AI code editor. According to Foresight News, the extension was disguised as a legitimate Solidity plugin but functioned as a cross-platform malware delivery tool that could establish persistence on a device and receive remote control commands, posing risks to developers’ private keys, wallets, and on-chain assets.
Attackers used Ethereum smart contracts to dynamically store and update the address of the remote control server, allowing them to switch attack endpoints without republishing the extension. The extension had been removed from Open VSX, but it was still available through the TRAE plugin marketplace as of July 18. SlowMist advised users who had installed juannegro.solidity to uninstall it immediately and check their systems for possible intrusion.
AI TRENDS | SlowMist Flags Malicious TRAE Extension Targeting Developers’ Keys and Wallets
2026-07-20 08:43:42
Disclaimer:
1. The information provided does not constitute investment advice. Investors should make independent decisions and bear all risks themselves.
2. The copyright of this content belongs to the original author. The views expressed herein are solely those of the author and do not represent the stance or position of this website.
Previous article:
港交所:先研究延长衍生产品交易时段