GlassWASM Malware in Trojanized Open VSX Extensions Uses Solana for C2

Summary
Socket researchers found TinyGo-compiled WebAssembly malware in two impersonated Open VSX extensions. It decrypts strings at runtime, uses Solana transaction memos to retrieve rotating C2 hosts, and launches OS-specific second-stage scripts.
Key points
- Two malicious Open VSX extensions—ExarGD/vsblack@0.0.1 and noellee-doc/flint-debug@0.1.1—impersonated legitimate extensions and automatically ran a TinyGo-compiled WebAssembly payload on activation.
- The malware encrypts important strings with ChaCha20 and reconstructs them at runtime, leaving network indicators absent from the raw WebAssembly file.
- It polls a hardcoded Solana wallet for transaction memos, which supply a changeable second-stage host; the researchers resolved dodod[.]lat at the time of analysis.
- The malware uses Node.js child_process to run platform-specific download-and-execute commands: curl piped to bash on macOS/Linux and PowerShell on Windows.
- Researchers assess the campaign as GlassWorm-associated with medium confidence, citing shared Solana dead-drop tradecraft and Open VSX delivery.
- Open VSX removed the reported extensions. The second-stage server did not serve payloads during analysis, so the attacker’s ultimate intent was unconfirmed.
- The researchers recommend removing the Open VSX copies, investigating systems where they ran, and rotating credentials accessible to those environments.
Article Details
- Attack Vectors
- Trojanized extension clones were published on Open VSX under impersonated publisher namespaces, reproducing legitimate extensions' names, versions, descriptions, README files, and repository links.
- An onStartupFinished activation hook automatically runs an appended JavaScript bootstrap that loads a compiled WebAssembly payload.
- The payload reconstructs ChaCha20-encrypted strings in memory, reads an attacker-supplied host from blockchain transaction memos, and constructs platform-specific download-and-execute commands.
- Second-stage scripts are requested over HTTPS and passed directly to shell interpreters through the JavaScript host's process-execution interface.
- Defensive Notes
- Remove the malicious Open VSX copies and hunt extension directories fleet-wide. The original verified VS Code Marketplace listings were reported clean; removal should be scoped to the Open VSX builds.
- The Open VSX security team removed the reported packages and malicious publisher after notification.
- Monitor unexpected blockchain JSON-RPC activity from editor-related JavaScript runtimes, particularly signature enumeration followed by transaction retrieval and memo parsing. Do not indiscriminately block the legitimate public RPC service.
- Detect editor-related JavaScript runtimes spawning shells or download utilities, download commands piped into interpreters, and process creation with window-hiding options.
- Inspect packages containing WebAssembly modules and small JavaScript instantiation shims. Host-bridge imports can reveal modules capable of driving network requests and process execution.
- Static URL and wallet-string signatures will not match the encrypted WebAssembly artifact; use runtime memory inspection, behavioral telemetry, and deobfuscation.
- Re-resolve the watched wallet's latest memo periodically because the operator can rotate second-stage infrastructure without updating the extension.
- The source recommends rotating developer, CI, cloud, and package-publishing credentials accessible from hosts that executed the module.
- At analysis time, the resolved server did not serve second-stage payloads. Ultimate payload capabilities and attacker intent were not confirmed; detection or server-side victim gating were offered as possible explanations.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | dodod[.]lat | Defanged C2 and second-stage host resolved from the watched wallet's memos as of 2026-06-11. |
| IPV4 | 217[.]69[.]3[.]152 | Historical GlassWorm C2 cited with the /wall path, not identified as this variant's infrastructure. |
| IPV4 | 45[.]150[.]34[.]158 | Historical GlassWorm exfiltration host cited for comparison. |
| IPV4 | 45[.]32[.]150[.]251 | Historical GlassWorm C2 cited for comparison with this variant's new infrastructure. |
| MD5 | 4e143876eeaf5e767a9971f603b0f13c | Source-reported MD5 of the malicious WebAssembly artifact. |
| MD5 | b262b8d2ac2f0ab3c78251db44ecf3ac | Source-reported MD5 of the trojanized noellee-doc.flint-debug-0.1.1.vsix package. |
| MD5 | f595fb7867beb76b4deab53fa328e0a2 | Hash of the trojanized exargd.vsblack-0.0.1.vsix package. |
| SHA1 | 824e601b599b9ad97ee12f0b3a72efd20ba59d47 | Hash of the trojanized exargd.vsblack-0.0.1.vsix package. |
| SHA1 | 8ebac142e34a20c297d3ccaca7ee5d9ddd24fed4 | Source-reported SHA-1 of the malicious WebAssembly artifact. |
| SHA1 | c0ed7d575fe8085e942898c9a26f15992c895ba9 | Source-reported SHA-1 of the trojanized noellee-doc.flint-debug-0.1.1.vsix package. |
| SHA256 | 1e283327ad048bea39f4a8501770858a20f3555e87fe3e202274f2e87f8a3c25 | Hash of the trojanized exargd.vsblack-0.0.1.vsix package. |
| SHA256 | 3aa31999398e7f80231c03d7137ffdb554a84b83dbcffc59ce16c9a65f9e5d58 | Hash of the trojanized noellee-doc.flint-debug-0.1.1.vsix package. |
| SHA256 | 558b4f1d9a263c13756ab0126c09dd080c85ba405b29488e1c4e6aa68b554f1f | Hash of the malicious WebAssembly artifact identified as orybbbdsuqmaapel.wasm / snqpkebiwrxmoivl.wasm. |
| URL | hxxps[:]//dodod[.]lat/darwin/i/_ | Defanged macOS second-stage download URL listed in the source's indicators. |
| URL | hxxps[:]//dodod[.]lat/linux/i/_ | Defanged Linux second-stage download URL listed in the source's indicators. |
| URL | hxxps[:]//dodod[.]lat/win32/i/_ | Defanged Windows second-stage download URL listed in the source's indicators. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe loader's decision logic is compiled into WebAssembly with stripped names, and consequential strings are encrypted with ChaCha20.T1036 · MasqueradingMalicious extensions copied verified originals' publisher IDs, names, versions, descriptions, README files, and repository links to impersonate trusted packages.T1059.001 · PowerShellThe Windows branch constructs a PowerShell command that pipes Invoke-RestMethod output into Invoke-Expression.T1059.004 · Unix ShellThe macOS and Linux branches construct curl download commands piped directly into bash.T1059.007 · JavaScriptAn appended JavaScript bootstrap instantiates the module, whose host bridge invokes fetch and require('child_process').execSync.T1071.001 · Web ProtocolsThe JavaScript host sends HTTPS JSON-RPC requests to retrieve transaction signatures and memo-bearing transactions used for C2 resolution.T1102.001 · Dead Drop ResolverThe module reads attacker-posted Solana transaction memos as a dead-drop that resolves a rotating second-stage host.T1105 · Ingress Tool TransferThe loader constructs HTTPS retrieval commands for operating-system-specific second-stage scripts; the server did not deliver those payloads at analysis time.T1140 · Deobfuscate/Decode Files or InformationThe module decrypts URLs, addresses, and commands into linear memory at runtime before using them.T1195.002 · Compromise Software Supply ChainAttackers distributed trojanized editor extensions through Open VSX, carrying an automatically activated WebAssembly loader.T1564.003 · Hidden WindowThe module passes windowsHide:true to child_process.execSync to suppress the child console window on Windows.
People
Threat Actors
Malware
GlassWASMa stager suggests a new pivot to binary loading for obfuscation purposes. We have labeled this family “GlassWASM” to highlight this connection.GlassWormas well as some key shared artifacts, we attribute this campaign with medium confidence to the GlassWorm developer. However, the use of WebAssembly/TinyGo ****as a stager suggests a new pivot to binary loading
Products
Cursorwho finds "Flint Debug 0.1.1" or "VSBlack 0.0.1" on Open VSX — the default registry for VSCodium, Gitpod, Cursor, Windsurf, and other VS Code forks — sees a name, version, description, and repo link that all match theExarGD.vsblacklow-profile, long-dormant open source projects whose authors are unlikely to be monitoring Open VSX: ExarGD.vsblack is a black-background variant of the popular dunstontc.dark-plus-syntax theme, published to the VSGitpodwho finds "Flint Debug 0.1.1" or "VSBlack 0.0.1" on Open VSX — the default registry for VSCodium, Gitpod, Cursor, Windsurf, and other VS Code forks — sees a name, version, description, and repo link that allNode.jsHost required: JavaScript runtime (Node.js / browser) via syscall/js bridgenoellee-doc.flint-debugnoellee-doc.flint-debug is an academic Ethereum/Flint smart-contract debugger by Noel Lee of Imperial College, published in June 2020 (repo github[.]com/noellee/vscode-flint-debug).Open VSXStudio Code. At the time of publication, we identified the following affected package versions on the Open VSX marketplace:TinyGoThese extensions ship a WebAssembly payload behind a renamed TinyGo loader, and both auto-execute it on extension activation via an appended bootstrap that instantiates the module with go.run(). The fake-utility framingVisual Studio CodeResearch team discovered compiled WebAssembly malware embedded in trojanized code extensions for Visual Studio Code. At the time of publication, we identified the following affected package versions on the Open VSXVS Code MarketplaceThe two carriers are trojanized clones of legitimate, verified VS Code Marketplace extensions, re-published on the Open VSX registry under impersonated publisher namespaces. A single Open VSX account, zaitoona43 (GitHubVSCodiumBut a developer who finds "Flint Debug 0.1.1" or "VSBlack 0.0.1" on Open VSX — the default registry for VSCodium, Gitpod, Cursor, Windsurf, and other VS Code forks — sees a name, version, description, and repo linkWindsurf"Flint Debug 0.1.1" or "VSBlack 0.0.1" on Open VSX — the default registry for VSCodium, Gitpod, Cursor, Windsurf, and other VS Code forks — sees a name, version, description, and repo link that all match the trusted
Tools
wasm-objdump# Imports (wasm-objdump -j Import -x) — 17 totalwasm2ck is the ChaCha/Salsa sigma constant and is used by nothing else. Translating the module to C with wasm2c and locating the rotation-heavy function confirms a textbook ChaCha20 implementation — the canonicalYARAnaïve key extraction. For defenders, the practical consequence is that static string scanning and YARA rules keyed on URLs or the wallet address will not fire on this file. The indicators exist only after