Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Zammad Zero-Day Exploited to Hijack Sessions, Execute Code
October 5, 2026
Researcher Infiltrates Lazarus Group Crypto Laundering After Bybit Hack
October 5, 2026
Google Gemini AI to gain full computer access: What it means for users
October 5, 2026
Home/Threats/GlassWorm Supply Chain Attack Hides Malware in Fake VS Code Themes
Threats

GlassWorm Supply Chain Attack Hides Malware in Fake VS Code Themes

Key Takeaways The GlassWorm supply chain attack leverages malicious VS Code extensions disguised as popular themes to deliver malware. Two extensions, “Aurora Nocturne Night Theme” and...

David kimber
David kimber
October 5, 2026 5 Min Read
3 0

Key Takeaways

  • The GlassWorm supply chain attack leverages malicious VS Code extensions disguised as popular themes to deliver malware.
  • Two extensions, “Aurora Nocturne Night Theme” and “Cosmic Nebula Themes,” were confirmed malicious, with a third, “Coca-Cola Christmas,” flagged as high-risk due to suspicious executable functionality.
  • The malware employs obfuscated JavaScript, Unicode character encoding, and Solana blockchain transaction memos for payload delivery and stealth.
  • Compromised developer workstations pose significant risks, potentially leading to credential theft and unauthorized access to source code repositories and cloud environments.
  • Microsoft has removed the reported extensions from the Visual Studio Marketplace, but users must manually remove installed copies and investigate potential compromise.

GlassWorm Attack Exploits VS Code Themes

The GlassWorm campaign has been identified turning legitimate developer tools into conduits for malware, specifically by distributing malicious extensions masquerading as visually appealing themes for Visual Studio Code (VS Code). This sophisticated supply chain attack, first detected in October 2025, has since expanded its reach across both the Visual Studio Marketplace and Open VSX, highlighting a concerning trend where seemingly innocuous cosmetic changes conceal executable code designed to compromise developer machines.

Table Of Content

  • Key Takeaways
  • GlassWorm Attack Exploits VS Code Themes
  • Malicious Extensions Identified
  • How the Attack Operates
  • Attribution and Infrastructure
  • What You Should Do
  • Indicators of Compromise (IoCs)

Previous reports on GlassWorm’s tactics within developer tools revealed its capacity for stealing credentials and establishing persistent access. These capabilities render infected developer workstations highly valuable targets, serving as potential entry points into critical resources like code repositories, cloud environments, and other sensitive corporate assets.

Malicious Extensions Identified

Researchers at Socket.dev have pinpointed a cluster of ten extensions across the Visual Studio Marketplace (four listings) and Open VSX (six identities) that are linked to this theme-based attack. In a detailed report shared with Cyber Security News (CSN), Socket.dev confirmed two extensions as explicitly malicious, with one demonstrating a strong technical correlation to the GlassWorm operation.

While the analysis differentiated between confirmed malware and associated extensions lacking active payloads in the versions examined, the scale of the potential impact is notable. “Coca-Cola Christmas” and “Aurora Borealis Studio Theme” collectively garnered over 8,000 installations on the Marketplace. Furthermore, related Open VSX listings accumulated tens of thousands of downloads. It is important to note that these download figures do not definitively indicate the total number of compromised users.

How the Attack Operates

The “Aurora Nocturne Night Theme” extension was found to contain a hidden Windows downloader within its distributed package, a malicious component absent from its publicly available source code repository. This discrepancy underscores a critical challenge: relying solely on public repository reviews can fail to detect such threats. The executable JavaScript within the extension was heavily obfuscated, compressed into a single line of approximately 59 KB, and utilized invisible Unicode characters to encode its payload.

Upon successful decoding of these concealed instructions, the extension proceeds to download content from an attacker-controlled server. It then saves a temporary Windows command script and executes it silently, without displaying any command prompt window to the user. This stealthy execution allows the malware to operate undetected.

This pattern of deception mirrors earlier GlassWorm attacks involving malicious icon theme extensions, which also combined normal visual functionality with hidden malware execution. In the current cluster, attackers leveraged familiar commercial branding and names that mimicked popular themes to enhance the credibility of suspicious packages, often bypassing initial scrutiny of the publisher’s identity.

Attribution and Infrastructure

Investigators established connections between several projects by examining Git histories, revealing shared contributors. Further corroborating evidence included identical theme definitions, recurring Russian-language comments, and reused welcome-page code across different projects. A notable finding was five commits on December 6, 2025, occurring within roughly three hours and all using the same timezone offset, indicating coordinated activity. Socket.dev also uncovered a December 14, 2025, article that promoted several of these linked themes as independent recommendations. Based on the broader development evidence, researchers concluded this article served as promotional infrastructure for the operation rather than an unbiased review.

The “Cosmic Nebula Themes” extension provided the definitive link to GlassWorm. Its Marketplace build incorporated an embedded JavaScript component, encrypted with AES-256-CBC, which was immediately decrypted and executed upon installation. This recovered loader was designed to evade systems configured with Russian language settings or timezones. It then communicated with Solana blockchain transaction memos to identify and retrieve additional payload infrastructure.

This novel mechanism allows attackers to dynamically alter the subsequent download location without needing to publish a new version of the extension. The retrieved JavaScript then executes in memory, gaining access to the host system’s capabilities. The congruence of the shared blockchain address, encryption key, and execution methodology with previously documented GlassWorm activities provided Socket.dev with high confidence in its attribution.

However, shared development patterns do not definitively prove that every publisher account belongs to a single individual, nor does it automatically render every related version actively malicious. While Socket found no active payload in the analyzed versions of “Coca-Cola Christmas” and “Aurora Borealis Studio Theme,” their inclusion of unnecessary executable functionality was deemed a high-risk indicator.

What You Should Do

  • Remove Malicious Extensions Immediately: If you have installed “microsoftvs.microsoftvs” (Aurora Nocturne Night Theme) or “cosmic-themes.theme-cosmic-nebula” (Cosmic Nebula Themes), remove them from your VS Code environment. Note that Marketplace removal does not clean installed copies.
  • Investigate Compromise: For any host where a malicious extension was installed and the downloaded command script ran, assume compromise. Conduct a thorough forensic investigation for credential theft, unauthorized access, and persistence. Use the provided Indicators of Compromise (IoCs) to aid your investigation.
  • Review All Extensions: Inventory all VS Code extensions across Visual Studio Marketplace and Open VSX. Scrutinize extensions, especially themes, for unnecessary executable functionality, network access, or process launch capabilities.
  • Verify Publishers: Before installing any extension, thoroughly verify the publisher’s legitimacy and reputation, not just the appeal of the theme or functionality. Be wary of new accounts or those with limited history.
  • Monitor for Updates: Implement a process to compare extension versions after updates. Malicious payloads can be introduced in later, seemingly harmless updates. Do not assume an initially benign installation remains secure indefinitely.
  • Implement Runtime Analysis: Inspect installed packages, including activation settings, bundled scripts, network activity, process launches, and runtime decryption, to detect hidden malicious components.
  • Stay Informed: Regularly review security intelligence for new threats targeting developer tools and supply chains.

Indicators of Compromise (IoCs)

Type Indicator Description
Malicious extension microsoftvs.microsoftvs Confirmed malicious Marketplace package advertised as Aurora Nocturne Night Theme.
SHA-256 a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07 Aurora Nocturne Night Theme VSIX/ZIP package.
SHA-256 5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268 Aurora Nocturne Night Theme executable JavaScript.
File path out/extension.js Obfuscated executable containing the Aurora Nocturne downloader.
Domain fingercakes4sale[.]store Attacker-controlled payload delivery domain.
Payload URL hxxps://fingercakes4sale[.]store/dsyuC Download location recovered from the concealed loader.
Dropped file %TEMP%temp_batch.cmd Downloaded Windows command script.
File name temp_batch.cmd Command script basename used by the downloader.
Process cmd.exe Windows command interpreter used to execute the downloaded script.
Execution command cmd.exe /c "<TEMP_PATH>temp_batch.cmd" Execution pattern documented for Aurora Nocturne Night Theme.
Malicious extension cosmic-themes.theme-cosmic-nebula Confirmed malicious Marketplace build of Cosmic Nebula Themes; also a cluster-linked Open VSX identity.
SHA-256 684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804 Cosmic Nebula Themes executable JavaScript.
SHA-256 da2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb Decrypted embedded stage recovered from Cosmic Nebula Themes.
File name app.js Cosmic Nebula executable entrypoint; related projects also use this filename for benign-looking theme functionality.
Solana address

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

macOS Sonoma 14.4 Enhances Full Disk Access Security

Next Post

RemoveMacAI Tool Deletes Apple Intelligence Models, Frees 12GB Storage

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GlassWorm Supply Chain Attack Hides Malware in Fake VS Code Themes
October 5, 2026
macOS Sonoma 14.4 Enhances Full Disk Access Security
October 5, 2026
Google Pauses Open-Source Bug Bounty Program Due to AI-Generated Spam
October 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us