WebAssembly Malware Found in Trojanized Open VSX Extensions

June 16, 2026, 11:18 a.m.

Description

Trojanized Visual Studio Code extensions distributed via the Open VSX marketplace deliver a sophisticated WebAssembly-based attack chain. The extensions ship ChaCha20-encrypted TinyGo-compiled WebAssembly modules that poll the Solana blockchain for command-and-control instructions embedded in transaction memos. This novel dead-drop technique allows attackers to rotate infrastructure without hardcoded servers. Once activated, the modules read attacker instructions from a monitored Solana wallet address, then execute platform-specific download-and-execute commands via Node.js child_process to deploy second-stage payloads. The campaign impersonates legitimate extensions on Open VSX, exploiting cross-registry trust gaps to target VSCodium, Cursor, Windsurf, and other VS Code forks. Attribution points to GlassWorm-associated tradecraft with medium confidence, representing a new WebAssembly-based variant of previously documented supply chain compromise techniques.

Date

  • Created: June 16, 2026, 4:27 a.m.
  • Published: June 16, 2026, 4:27 a.m.
  • Modified: June 16, 2026, 11:18 a.m.

Indicators

  • 558b4f1d9a263c13756ab0126c09dd080c85ba405b29488e1c4e6aa68b554f1f
  • 3aa31999398e7f80231c03d7137ffdb554a84b83dbcffc59ce16c9a65f9e5d58
  • 1e283327ad048bea39f4a8501770858a20f3555e87fe3e202274f2e87f8a3c25
  • 45.150.34.158
  • https://dodod.lat/darwin/i/_
  • http://dodod.lat/win32/i/_
  • https://dodod.lat/win32/i/_
  • http://dodod.lat/linux/i/_
  • http://dodod.lat/darwin/i/_
  • https://dodod.lat/
  • https://dodod.lat/linux/i/_

Additional Informations

  • Technology
  • dodod.lat