WebAssembly Malware Found in Trojanized Open VSX Extensions
Reported 16 Jun 2026 by otx · Severity: medium
Trojanized Visual Studio Code extensions distributed via the Open VSX marketplace deliver a sophisticated WebAssembly-based attack chain. The extensions ship ChaCha20-encrypted TinyGo-compiled WebAssembly modules that poll the Solana blockchain for command-and-control instruction