GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
ID: 3f105854-b874-55f8-96db-9c6f1531979a
STIX ID: report--3f105854-b874-55f8-96db-9c6f1531979a
Feed Name: Socket Blog
**Executive summary:** Socket Threat Research discovered trojanized Open VSX VS Code extensions that ship a TinyGo-compiled WebAssembly payload which decrypts strings in-memory, polls a Solana wallet for SPL Memo instructions to obtain a rotating C2 host (dodod.lat), and uses Node's child_process to run platform-specific download-and-execute commands; the report provides file hashes, affected packages, behavioral indicators, mitigation guidance, and attributes the sample with medium confidence to the GlassWorm campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
