Malicious VS Code Themes Tied to GlassWorm Supply Chain
Socket says GlassWorm-linked VS Code themes on two registries hid malware loaders; Microsoft removed Marketplace copies, but sources differ on how many were malicious.
On 5 October 2026, Socket Threat Research linked VS Code color-theme extensions, including Cosmic Nebula Themes and Aurora Nocturne Night Theme, on the Visual Studio Marketplace and Open VSX Registry to the GlassWorm supply-chain campaign, which one report says previously stole credentials and sought persistence on developer machines. Cosmic Nebula Themes decrypted an embedded stage with AES-256-CBC, executed it via eval(), and read Solana transaction memos at BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC to rotate command-and-control and deliver follow-on JavaScript that runs in memory with Node.js require, Buffer, and process access; one report adds that the loader skipped Russian-language or Russian-timezone systems. Aurora Nocturne Night Theme used zero-width Unicode obfuscation to hide a Windows downloader that contacted fingercakes4sale[.]store and executed %TEMP%\temp_batch.cmd. The reports disagree on the wider cluster: one says Russian-language comments and shared Git identities link six extensions and that Coca-Cola Christmas and Aurora Borealis Studio Theme drew over 8,000 Marketplace installs plus tens of thousands of Open VSX downloads, while the other says only two Marketplace extensions were confirmed malicious, only one was tied to GlassWorm, and those two themes had no active payload in the analyzed builds despite more than 8,000 combined installs. Microsoft removed the reported Marketplace extensions after disclosure, though installed copies can remain, and the malicious themes ran JavaScript on every VS Code session even though themes normally need only declarative configuration.
- Socket Threat Research reports dated 2026-10-05 linked VS Code color-theme extensions on the Visual Studio Marketplace and Open VSX Registry to the GlassWorm supply-chain campaign, previously described as stealing credentials and seeking…
- Cosmic Nebula Themes decrypted an embedded stage with AES-256-CBC, ran it via eval(), and used Solana transaction memos at BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC to rotate C2 and deliver in-memory JavaScript with Node.js require,…
- One report says the Cosmic Nebula loader skipped Russian-language or Russian-timezone systems.
- Aurora Nocturne Night Theme hid a Windows downloader with zero-width Unicode obfuscation that contacted fingercakes4sale[.]store and executed %TEMP%\temp_batch.cmd.
- Sources disagree on cluster size: Russian-language comments and shared Git identities linking six extensions, versus two Marketplace extensions confirmed malicious and only one linked to GlassWorm.
- Coca-Cola Christmas and Aurora Borealis Studio Theme: one account cites over 8,000 Marketplace installs plus tens of thousands of Open VSX downloads; the other says combined installs exceeded 8,000 and the analyzed builds had no active…
- Microsoft removed the reported Marketplace extensions after disclosure; installed copies can remain, and the malicious themes executed JavaScript on every VS Code session.
Coverage timelineoldest first · each row is one article
- · 3d agoGlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes
GBHackers· 78
GlassWorm-linked malicious VS Code color themes on Visual Studio Marketplace and Open VSX shipped staged JavaScript loaders that pulled C2 addresses from Solana memos.
- · 3d agoGlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware
Cyber Security News· 78
GlassWorm-linked VS Code theme extensions hide downloaders that fetch Windows malware, including a blockchain-addressed in-memory loader.