๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
๊ฐ€์ž… April 2018
408 ํŒ”๋กœ์ž‰ ์ค‘    88.8K ํŒฌ
๐Ÿšจ Threat Intelligence | On-Chain Backdoor in a Malicious TRAE Extension Following @Will42Wโ€™s warning about TRAE IDE extension supply chain risks, SlowMist investigated the malicious extension juannegro.solidity. Although removed from Open VSX, the extension was still available through the TRAE marketplace as of July 18, 2026. It impersonated a legitimate Solidity plugin and acted as a cross-platform malware dropper. Our analysis found that it: ๐Ÿ”น Impersonates a legitimate Solidity extension and uses the marketplace as the initial malware delivery channel ๐Ÿ”น Automatically executes after IDE startup and establishes persistence across platforms ๐Ÿ”น Uses an Ethereum smart contract to store and retrieve dynamic C2 configurations ๐Ÿ”น Allows attackers to update C2 endpoints and payload delivery without republishing the extension This incident highlights how extension marketplaces can become initial infection vectors, while blockchain infrastructure can be abused for dynamic C2 management. Users who installed juannegro.solidity should remove the extension and check their systems for potential compromise. Full analysis๐Ÿ‘‡
๋” ๋ณด๊ธฐ