Svmuu News: According to monitoring by SlowMist, the malicious TRAE IDE extension "juannegro.solidity" masquerades as a Solidity plugin and acts as a cross-platform malware deliverer.The extension automatically executes and establishes persistence upon IDE startup. It also uses the smart contract at Ethereum to store and retrieve dynamic C2 configurations, allowing attackers to update C2 endpoints and payloads without having to republish the extension.Although the extension has been removed from Open VSX, as of July 18, it was still available via the TRAE marketplace. Users who have installed it should immediately uninstall it and check their systems for compromise.