#GlassWASM
New Research: Trojanized Open VSX extensions are shipping GlassWASM, a new WebAssembly malware variant.

It hides malware logic in TinyGo-compiled WASM and pulls C2 instructions from Solana transaction memos.

socket.dev/blog/glasswa...
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ...
The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.
socket.dev
June 16, 2026 at 1:10 AM
-New malware: Rokarolla, GlassWASM, Backdoor.Turn, Scales, Potemkin loader
-New UNC6508 group targets REDCap servers
-New Cisco SD-WAN zero-day
-New LiteSpeed zero-day
-CVE program on pace for record year
-New SearchLeak vulnerability
-Hacker hijacks half of Monero's P2Pool
June 17, 2026 at 7:32 AM
@socket.dev
GlassWASM malware found in trojanized Open VSX extensions uses WebAssembly and Solana blockchain for evasive C2.
-
IOCs: dodod[. ]lat, github[. ]com/zaitoona43, 558b4f1d9a263c13756ab0126c09dd080c85ba405b29488e1c4e6aa68b554f1f
-
...
GlassWASM Malware in Open VSX
socket.dev
June 16, 2026 at 4:04 AM
GlassWASM Malware Exposes a New Stealth Attacks: Trojanized VS Code Extensions Turn Open Source Tools Into Hidden Backdoors

Introduction: When Developer Trust Becomes the New Attack Surface The software development ecosystem has become one of the most attractive targets for modern cybercriminals…
GlassWASM Malware Exposes a New Stealth Attacks: Trojanized VS Code Extensions Turn Open Source Tools Into Hidden Backdoors
Introduction: When Developer Trust Becomes the New Attack Surface The software development ecosystem has become one of the most attractive targets for modern cybercriminals because developers often have privileged access to source code, cloud environments, internal systems, and production infrastructure. A single compromised development tool can become a silent gateway into organizations that would otherwise have strong security defenses. A recent discovery by security researchers has revealed a sophisticated malware campaign involving trojanized Open VSX Visual Studio Code extensions.
undercodenews.com
June 16, 2026 at 8:01 PM
Trojanized Open VSX VS Code extensions were found delivering a TinyGo-compiled WebAssembly payload and using Solana memos as a takedown-resistant C2 dead drop. #GlassWASM #OpenVSX #Solana
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
Socket’s Threat Research team uncovered trojanized Open VSX Visual Studio Code extensions that delivered a TinyGo-compiled WebAssembly payload and used Solana memos as a takedown-resistant command-and-control dead drop. The campaign, attributed with medium confidence to the GlassWorm developer, was dubbed “GlassWASM” and involved packages impersonating ExarGD.vsblack and noellee-doc.flint-debug. #GlassWASM #OpenVSX #Solana #GlassWorm
www.hendryadrian.com
June 16, 2026 at 3:15 PM
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX Extensions
socket.dev
June 17, 2026 at 7:24 AM