Home / Companies / Socket / Blog / Post Details
Content Deep Dive

GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions

Blog post from Socket

Post Details
Company
Date Published
Author
Joseph Edwards
Word Count
3,923
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Socket Threat Research team uncovered a sophisticated malware campaign utilizing WebAssembly embedded in Visual Studio Code extensions, targeting crypto developers through trojanized clones of legitimate extensions on the Open VSX marketplace. These extensions contain a WebAssembly module, obfuscated using ChaCha20 encryption, which activates upon extension launch to communicate with the Solana blockchain for command-and-control instructions. The malware exploits a JavaScript host environment to execute OS-specific download-and-run commands, bypassing traditional detection methods by storing its C2 instructions on the blockchain, rather than hardcoded servers, making it resilient to takedown efforts. This campaign is attributed with medium confidence to the GlassWorm developer, known for utilizing Solana transaction memos as a dead-drop mechanism and employing a novel approach by using TinyGo-compiled WebAssembly for obfuscation. The affected extensions were quickly removed from the registry following the discovery, and defenders are advised to monitor for suspicious activities, such as unexpected blockchain interactions and process executions, to mitigate potential threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 2,515 393 134 +17%
Vector Search 1 1,897 384 134 -16%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.