The security firm SlowMist has issued an urgent warning regarding a malicious extension discovered within the TRAE IDE market. The plugin, identified as juannegro.solidity, masquerades as a legitimate tool for Solidity developers but functions as a sophisticated cross-platform malware dropper. This incident represents a growing trend where attackers exploit developer environments and blockchain infrastructure to maintain persistent access to compromised systems.
Mechanism of the juannegro.solidity Malware
Analysis by the SlowMist security team reveals that the extension initiates its malicious activity immediately upon the startup of the Integrated Development Environment (IDE). Once active, it establishes a persistence mechanism that allows it to remain on the host system despite reboots or IDE restarts. The primary danger lies in its ability to act as a gateway for further malware payloads, potentially exposing sensitive private keys, source code, and personal credentials.
- Initial Infection Vector: The TRAE extension market, specifically targeting blockchain developers.
- Execution Style: Automatic activation upon IDE launch.
- Cross-Platform Capability: Designed to function across different operating systems used by developers.
Blockchain Infrastructure Abused for C2 Management
A notable feature of this attack is the use of Ethereum smart contracts to manage Command and Control (C2) configurations. By storing C2 endpoints on-chain, attackers can dynamically update their infrastructure without needing to modify or re-release the extension itself. This on-chain backdoor makes the malware significantly harder to neutralize through traditional domain blacklisting.
By leveraging the immutable and decentralized nature of the Ethereum blockchain, the perpetrators ensure that the malware can always retrieve the latest instructions from a source that cannot be easily taken down by centralized authorities.
Current Status and Mitigation Steps
As of July 18, 2026, the extension had been removed from the Open VSX registry; however, it remained accessible through the TRAE market for a period afterward. SlowMist advises all developers to audit their IDE environments immediately.
SlowMist reminds users who have installed the extension to remove it immediately and check their systems for compromise.
Security experts recommend that users who have interacted with the plugin should not only uninstall the software but also conduct a thorough system scan and rotate any cryptographic keys or passwords that may have been stored on the infected machine. This event highlights the critical need for supply chain security within the cryptocurrency and software development ecosystems.
In conclusion, the discovery of the juannegro.solidity malware underscores the evolving tactics of cybercriminals who now utilize blockchain technology to enhance the resilience of their attack infrastructure. As extension markets become primary targets for infection, developers must exercise increased vigilance when integrating third-party plugins into their workflow. Monitoring for unusual network activity and staying informed via security alerts from firms like SlowMist remains essential for maintaining digital asset security.
Frequently Asked Questions
Quick answers to the most common questions about this topic.