GlassWorm Supply Chain Attack Hides Malware in Fake VS Code Themes
Key Takeaways The GlassWorm supply chain attack leverages malicious VS Code extensions disguised as popular themes to deliver malware. Two extensions, “Aurora Nocturne Night Theme” and...
Key Takeaways
- The GlassWorm supply chain attack leverages malicious VS Code extensions disguised as popular themes to deliver malware.
- Two extensions, “Aurora Nocturne Night Theme” and “Cosmic Nebula Themes,” were confirmed malicious, with a third, “Coca-Cola Christmas,” flagged as high-risk due to suspicious executable functionality.
- The malware employs obfuscated JavaScript, Unicode character encoding, and Solana blockchain transaction memos for payload delivery and stealth.
- Compromised developer workstations pose significant risks, potentially leading to credential theft and unauthorized access to source code repositories and cloud environments.
- Microsoft has removed the reported extensions from the Visual Studio Marketplace, but users must manually remove installed copies and investigate potential compromise.
GlassWorm Attack Exploits VS Code Themes
The GlassWorm campaign has been identified turning legitimate developer tools into conduits for malware, specifically by distributing malicious extensions masquerading as visually appealing themes for Visual Studio Code (VS Code). This sophisticated supply chain attack, first detected in October 2025, has since expanded its reach across both the Visual Studio Marketplace and Open VSX, highlighting a concerning trend where seemingly innocuous cosmetic changes conceal executable code designed to compromise developer machines.
Table Of Content
Previous reports on GlassWorm’s tactics within developer tools revealed its capacity for stealing credentials and establishing persistent access. These capabilities render infected developer workstations highly valuable targets, serving as potential entry points into critical resources like code repositories, cloud environments, and other sensitive corporate assets.
Malicious Extensions Identified
Researchers at Socket.dev have pinpointed a cluster of ten extensions across the Visual Studio Marketplace (four listings) and Open VSX (six identities) that are linked to this theme-based attack. In a detailed report shared with Cyber Security News (CSN), Socket.dev confirmed two extensions as explicitly malicious, with one demonstrating a strong technical correlation to the GlassWorm operation.
While the analysis differentiated between confirmed malware and associated extensions lacking active payloads in the versions examined, the scale of the potential impact is notable. “Coca-Cola Christmas” and “Aurora Borealis Studio Theme” collectively garnered over 8,000 installations on the Marketplace. Furthermore, related Open VSX listings accumulated tens of thousands of downloads. It is important to note that these download figures do not definitively indicate the total number of compromised users.
How the Attack Operates
The “Aurora Nocturne Night Theme” extension was found to contain a hidden Windows downloader within its distributed package, a malicious component absent from its publicly available source code repository. This discrepancy underscores a critical challenge: relying solely on public repository reviews can fail to detect such threats. The executable JavaScript within the extension was heavily obfuscated, compressed into a single line of approximately 59 KB, and utilized invisible Unicode characters to encode its payload.
Upon successful decoding of these concealed instructions, the extension proceeds to download content from an attacker-controlled server. It then saves a temporary Windows command script and executes it silently, without displaying any command prompt window to the user. This stealthy execution allows the malware to operate undetected.
This pattern of deception mirrors earlier GlassWorm attacks involving malicious icon theme extensions, which also combined normal visual functionality with hidden malware execution. In the current cluster, attackers leveraged familiar commercial branding and names that mimicked popular themes to enhance the credibility of suspicious packages, often bypassing initial scrutiny of the publisher’s identity.
Attribution and Infrastructure
Investigators established connections between several projects by examining Git histories, revealing shared contributors. Further corroborating evidence included identical theme definitions, recurring Russian-language comments, and reused welcome-page code across different projects. A notable finding was five commits on December 6, 2025, occurring within roughly three hours and all using the same timezone offset, indicating coordinated activity. Socket.dev also uncovered a December 14, 2025, article that promoted several of these linked themes as independent recommendations. Based on the broader development evidence, researchers concluded this article served as promotional infrastructure for the operation rather than an unbiased review.
The “Cosmic Nebula Themes” extension provided the definitive link to GlassWorm. Its Marketplace build incorporated an embedded JavaScript component, encrypted with AES-256-CBC, which was immediately decrypted and executed upon installation. This recovered loader was designed to evade systems configured with Russian language settings or timezones. It then communicated with Solana blockchain transaction memos to identify and retrieve additional payload infrastructure.
This novel mechanism allows attackers to dynamically alter the subsequent download location without needing to publish a new version of the extension. The retrieved JavaScript then executes in memory, gaining access to the host system’s capabilities. The congruence of the shared blockchain address, encryption key, and execution methodology with previously documented GlassWorm activities provided Socket.dev with high confidence in its attribution.
However, shared development patterns do not definitively prove that every publisher account belongs to a single individual, nor does it automatically render every related version actively malicious. While Socket found no active payload in the analyzed versions of “Coca-Cola Christmas” and “Aurora Borealis Studio Theme,” their inclusion of unnecessary executable functionality was deemed a high-risk indicator.
What You Should Do
- Remove Malicious Extensions Immediately: If you have installed “microsoftvs.microsoftvs” (Aurora Nocturne Night Theme) or “cosmic-themes.theme-cosmic-nebula” (Cosmic Nebula Themes), remove them from your VS Code environment. Note that Marketplace removal does not clean installed copies.
- Investigate Compromise: For any host where a malicious extension was installed and the downloaded command script ran, assume compromise. Conduct a thorough forensic investigation for credential theft, unauthorized access, and persistence. Use the provided Indicators of Compromise (IoCs) to aid your investigation.
- Review All Extensions: Inventory all VS Code extensions across Visual Studio Marketplace and Open VSX. Scrutinize extensions, especially themes, for unnecessary executable functionality, network access, or process launch capabilities.
- Verify Publishers: Before installing any extension, thoroughly verify the publisher’s legitimacy and reputation, not just the appeal of the theme or functionality. Be wary of new accounts or those with limited history.
- Monitor for Updates: Implement a process to compare extension versions after updates. Malicious payloads can be introduced in later, seemingly harmless updates. Do not assume an initially benign installation remains secure indefinitely.
- Implement Runtime Analysis: Inspect installed packages, including activation settings, bundled scripts, network activity, process launches, and runtime decryption, to detect hidden malicious components.
- Stay Informed: Regularly review security intelligence for new threats targeting developer tools and supply chains.



No Comment! Be the first one.