logo

GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions

ID: 3f105854-b874-55f8-96db-9c6f1531979a

STIX ID: report--3f105854-b874-55f8-96db-9c6f1531979a

Feed Name: Socket Blog

Threat Score
78/100

Date Published: 2026-06-15

Date Updated: 2026-06-16

Author: Joseph Edwards

...
...

**Executive summary:** Socket Threat Research discovered trojanized Open VSX VS Code extensions that ship a TinyGo-compiled WebAssembly payload which decrypts strings in-memory, polls a Solana wallet for SPL Memo instructions to obtain a rotating C2 host (dodod.lat), and uses Node's child_process to run platform-specific download-and-execute commands; the report provides file hashes, affected packages, behavioral indicators, mitigation guidance, and attributes the sample with medium confidence to the GlassWorm campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.