GlassWASM Malware Hidden in Open VSX Extensions
ID: 88dae0b6-8f82-5cc3-b626-e2eb17bdb9a5
STIX ID: report--88dae0b6-8f82-5cc3-b626-e2eb17bdb9a5
Feed Name: securityonline.info
Researchers uncovered GlassWASM, a supply-chain malware campaign that trojanized Open VSX Visual Studio Code extensions to deliver a TinyGo-compiled WebAssembly loader which decrypts strings in memory, polls an attacker-controlled Solana wallet for memos to obtain a C2 host (resolved to dodod.lat), and executes OS-specific download-and-execute commands; packages were removed but defenders are advised to block the host and wallet, hunt for .wasm-as-extension loaders, monitor Node/PowerShell spawning download commands, and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
