Researchers discovered WebAssembly malware in trojanized extensions on Open VSX (exargd.vsblack@0.0.1, noellee-doc.flint-debug@0.1.1). The TinyGo-compiled modules, encrypted with ChaCha20, use Solana blockchain transactions as command-and-control dead-drops to target cryptocurrency wallet extensions and execute arbitrary downloads.