GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware
GlassWorm-linked VS Code theme extensions hide downloaders that fetch Windows malware, including a blockchain-addressed in-memory loader.
Socket reported a theme-extension cluster on the Visual Studio Marketplace and Open VSX tied to GlassWorm, which previously stole credentials and sought persistence on developer machines. Aurora Nocturne Night Theme hid an obfuscated Windows downloader that fetched a command script from fingercakes4sale[.]store and executed it. Cosmic Nebula Themes decrypted an embedded loader with AES-256-CBC, skipped Russian-language or Russian-timezone systems, and used Solana transaction memos as a dead drop for payloads that run in memory. Microsoft removed the reported Marketplace extensions; Coca-Cola Christmas and Aurora Borealis Studio Theme exceeded 8,000 combined installs but had no active payload in the analyzed builds.
- Two Marketplace extensions confirmed malicious; one linked to GlassWorm.
- Aurora Nocturne Night Theme downloads and runs a hidden Windows script.
- Cosmic Nebula Themes uses Solana memos to locate follow-on payloads.
- Microsoft removed the reported Marketplace listings; installed copies can remain.
- Theme packages drew thousands of installs across Marketplace and Open VSX.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | aurora.themes.dev | port-related domain connected to the cluster. Support email aurora.themes.dev@gmail[.]com Associated support identity documented by Socke |
| domain | fingercakes4sale.store | xecutable containing the Aurora Nocturne downloader. Domain fingercakes4sale[.]store Attacker-controlled payload delivery domain. Payload URL |
| domain | gmail.com | n connected to the cluster. Support email aurora.themes.dev@gmail[.]com Associated support identity documented by Socket. Note: I |
| domain | holiday-themes.dev | Nebula Themes development repository. Support email support@holiday-themes[.]dev Associated support identity; an investigative pivot, not |
| domain | outlook.com | nd Aurora Nocturne projects. Commit email aubineherodvulbdl@outlook[.]com Email associated with the shared commit identity. GitHub |
| md5 | 4c4b9a3773e9dced6015a670855fd32b | ly documented GlassWorm activity. AES initialization vector 4c4b9a3773e9dced6015a670855fd32b Initialization vector for the embedded encrypted stage. Res |
Full article1,212 words · extracted from cybersecuritynews.com · click to collapse
GlassWorm is turning developer tools into malware delivery channels, this time through extensions advertised as attractive VS Code themes.
The investigated cluster spans Visual Studio Marketplace and Open VSX, showing how appearance changes can provide cover for code that runs on developer machines. The campaign first surfaced in October 2025 and has since expanded across development platforms.
Earlier reporting on developer tools spreading GlassWorm describes credential theft and persistent access, risks that make compromised developer workstations valuable gateways into repositories, cloud environments, and other sensitive resources.
Researchers from Socket.dev identified four Marketplace extensions and six Open VSX identities linked to the theme cluster.
Socket.dev said in a report shared with Cyber Security News (CSN) that two extensions were confirmed malicious, with one showing a high-confidence technical connection to GlassWorm.
The findings distinguish confirmed malware from related extensions without active payloads. Coca-Cola Christmas and Aurora Borealis Studio Theme had more than 8,000 Marketplace installations combined.
Cluster-linked Open VSX listings attracted tens of thousands of downloads, although those totals do not establish how many users were compromised.
GlassWorm Supply Chain Attack
Aurora Nocturne Night Theme concealed a Windows downloader inside its distributed package, despite a public repository that appeared to provide theme functionality.
Its executable JavaScript was heavily disguised, compressed into roughly 59 KB on one line, and included a payload encoded with invisible Unicode characters.
After decoding the hidden instructions, the extension downloaded attacker-controlled content, saved a temporary Windows command script, and executed it without displaying a command window.
The discrepancy between public source code and the installed package explains why reviewing only a repository could miss the threat.
The disguise follows a pattern: earlier malicious icon theme extensions also combined normal visual behavior with concealed malware execution.
.webp)
In the newly investigated cluster, familiar commercial branding and names copying themes helped suspicious packages appear credible before users checked their publishers.
Git histories connected several projects through shared contributors, while matching theme definitions, recurring Russian-language comments, and reused welcome-page code strengthened the development links.
Five commits on December 6, 2025, occurred within roughly three hours and used the same timezone offset. Socket also identified a December 14, 2025, article promoting several linked themes as independent recommendations. Its publishing account was created that day.
Researchers assessed the article as promotional infrastructure for the operation, rather than an unrelated review, based on the wider development evidence.
GlassWorm Defenses
Cosmic Nebula Themes provided the GlassWorm connection. Its analyzed Marketplace build decrypted embedded JavaScript using AES-256-CBC encryption and immediately executed it.
The recovered loader avoided systems matching Russian-language or Russian-timezone conditions, then consulted Solana blockchain transaction memos to locate additional payload infrastructure.
That mechanism lets attackers change the next download location without publishing a new extension version. Retrieved JavaScript then runs in memory with access to system capabilities.
The shared blockchain address, encryption key, and execution pattern matched previously documented GlassWorm activity, supporting Socket’s high-confidence attribution.
However, shared development evidence does not prove every publisher account belongs to one individual. Nor does it make every related version actively malicious.
Socket found no active payload in the analyzed Coca-Cola Christmas and Aurora Borealis Studio Theme versions, but considered their unnecessary executable functionality high-risk.
Microsoft removed the reported Marketplace extensions after notification. Defenders should inventory themes across both registries and compatible editors, because marketplace removal does not clean installed copies.
Earlier GlassWorm malicious extension updates demonstrate why security reviews must continue after an initially harmless installation. Socket recommends inspecting the packages users install, including activation settings, bundled scripts, network access, process launches, and runtime decryption.
Teams should compare versions after updates and revisit assessments when new intelligence appears, rather than treating public repositories or one-time reviews as sufficient assurance.
Organizations exposed to either confirmed malicious extension should investigate subsequent execution and potentially exposed credentials.
A host where the downloaded command script ran should be treated as potentially compromised. Removing an extension cannot undo actions performed by follow-on payloads; the indicators below support that investigation.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.