The Latest Crypto News
Tuesday, 28 July 2026 BTC -- / --
🔍

Malicious Solidity Extension Abuses Ethereum Smart Contract as Backdoor

Make The Latest Crypto News preferred on Google
Ethereum symbol with a red 'malware' tag over Solidity code
Ethereum symbol with a red 'malware' tag over Solidity code

Security researchers at SlowMist have discovered a dangerous fraudulent extension in the TRAE IDE marketplace that uses an Ethereum smart contract as covert command and control infrastructure. The extension, named juannegro.solidity, posed as a legitimate Solidity plugin and was still targeting unsuspecting developers on 18 July 2026, even after the package had been removed from Open VSX.

How the attack works

The extension is a so-called cross-platform malware dropper, a piece of software that installs itself on the victim’s system and subsequently downloads additional malicious code. What makes this attack unique is that the attackers do not use ordinary servers to relay instructions; instead, they use a smart contract on the Ethereum blockchain. In that contract they store the addresses of their command and control servers, also known as C2 addresses.

This gives the attackers a significant advantage: they can change those addresses at any time without having to republish the extension. Security software that simply monitors fixed domains or IP addresses completely misses the attack. The malicious extension starts automatically upon launching the IDE and ensures it remains active after a reboot, on Windows, macOS and Linux alike. The Ethereum wallets linked to the attack are 0xf8a900db50b3331be6b768ba460bb59f3e40c344 and 0xFd3fc58bcbd8ccc77b6000201438eDfc636E7cA7.

Ethereum smart contract as attack weapon

Transaction data shows that the smart contract was already deployed in March 2026, months before the attack was discovered. The attackers used the contract to dynamically fetch payload addresses and reverse shell C2 locations. This allows them to redirect infected systems to new servers without changing a single line of code in the extension itself. This is a notable way of abusing blockchain technology for criminal purposes, similar to previous cases of malware being distributed through legitimate platforms.

SlowMist has published a comprehensive technical analysis of the attack. Developers who have installed the juannegro.solidity extension are strongly advised to remove it immediately and check their system for signs of compromise. The case highlights that IDE marketplaces are increasingly being used as an attack vector, and that attackers are making creative use of decentralised infrastructure to evade detection.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Hacks & Attacks News

More news ›