買幣
行情
現貨
合約
理財
活動
更多
reward-center新手專區
資訊首頁快訊詳情
SlowMist: TRAE Malicious Solidity Extension Exploits On-Chain Contract Dynamic Management C2 Configuration
  • ETH0%

BlockBeats News, July 20th, According to the security firm SlowMist, the malicious TRAE IDE extension juannegro.solidity disguised itself as a Solidity plugin and acted as a cross-platform malware delivery system. This extension would automatically execute upon IDE startup, establish persistence, and utilize an Ethereum smart contract to store and retrieve dynamic C2 configurations, allowing the attacker to update C2 endpoints and payloads without reissuing the extension. Although the extension has been removed from Open VSX, it was still available through the TRAE marketplace as of July 18th. Users who have installed it should immediately uninstall it and check if their systems have been compromised.

來源:BlockBeats

免責聲明:當前內容均來自第三方觀點或由AI直接翻譯第三方觀點,CoinEx不保證內容的真實性、準確性和原創性,不構成CoinEx相關的任何投資建議。數字資產價格波動劇烈,請注意潛在風險。

熱搜榜
  • 幣種
    價格
    24H漲跌