GlassWASM: Trojanized Open VSX Extensions Used TinyGo WebAssembly and Solana Memo C2
ConfirmedDiscovered Jun 20, 2026
Socket says two trojanized Open VSX extensions delivered a TinyGo-compiled WebAssembly loader that read Solana memo data to resolve `dodod[.]lat`, then built OS-specific download-and-execute commands for developer endpoints.
2
Affected Packages
24
Observables
3
Sources
Timeline
| Date | Event | Description | Source |
|---|---|---|---|
| Jun 20, 2026 | Fresh source review | Reviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data. | Direct source |
Affected Software
| Package | Ecosystem | Version Range | Status | Confidence | Source |
|---|---|---|---|---|---|
| exargd/vsblack | open-vsx | 0.0.1 | Malicious | 90% | Direct source |
| noellee-doc/flint-debug | open-vsx | 0.1.1 | Malicious | 90% | Direct source |
IOC Clipboard
20 IOCsdomain
api.mainnet.solana.comdomain
dodod.laturl
https://api.mainnet.solana.comurl
https://dodod.lat/darwin/i/_url
https://dodod.lat/linux/i/_url
https://dodod.lat/win32/i/_url
https://open-vsx.org/extension/exargd/vsblackurl
https://open-vsx.org/extension/noellee-doc/flint-debughash
558b4f1d9a263c13756ab0126c09dd080c85ba405b29488e1c4e6aa68b554f1fhash
8ebac142e34a20c297d3ccaca7ee5d9ddd24fed4hash
4e143876eeaf5e767a9971f603b0f13chash
3aa31999398e7f80231c03d7137ffdb554a84b83dbcffc59ce16c9a65f9e5d58hash
c0ed7d575fe8085e942898c9a26f15992c895ba9hash
b262b8d2ac2f0ab3c78251db44ecf3acfile_path
orybbbdsuqmaapel.wasmfile_path
snqpkebiwrxmoivl.wasmfile_path
noellee-doc.flint-debug-0.1.1.vsixfile_path
exargd.vsblack-0.0.1.vsixcommand
getSignaturesForAddresscommand
getTransactionProvenance & Sources
| Source | Type | Reliability | Claims | Evidence |
|---|---|---|---|---|
| Direct source | direct | 95% | 1 | https://open-vsx.org/extension/exargd/vsblack |
| Direct source | direct | 95% | 1 | https://open-vsx.org/extension/noellee-doc/flint-debug |
| Primary research | primary research | 95% | 1 | https://socket.dev/blog/glasswasm-malware-open-vsx-extensions |