GlassWorm loaders found hiding in popular VS Code colour themes

Socket says four theme extensions on the VS Code Marketplace and Open VSX are tied to the GlassWorm campaign, two of them confirmed malicious and using a Solana blockchain dead drop for command and control.

GlassWorm loaders found hiding in popular VS Code colour themes

At a glance

  • Socket Threat Research published its findings on October 2, naming Aurora Nocturne Night Theme and Cosmic Nebula Themes as confirmed malicious.
  • Coca-Cola Christmas and Aurora Borealis Studio Theme were flagged as high-risk but unweaponised, linked through shared Git history and executable scaffolding.
  • Cosmic Nebula reads its next payload address from memos attached to Solana blockchain transactions, so the operators can rotate servers without shipping an extension update.
  • Socket says Microsoft removed the reported extensions shortly after the report, but earlier published versions were not retroactively pulled.

Security firm Socket said on October 2 that four colour theme extensions published to the Visual Studio Code Marketplace and the Open VSX registry belong to the GlassWorm supply chain campaign, with two of them confirmed to deliver malware to developer machines. The research, credited to Kirill Boychenko of Socket Threat Research, matters because theme extensions are the category developers install most casually: they change syntax colours and are assumed to carry no executable code at all.

What happened

According to Socket, the cluster was tied together by shared Git history, reused source code and Russian-language developer comments. Two extensions were confirmed malicious: Aurora Nocturne Night Theme (publisher id microsoftvs.microsoftvs) and Cosmic Nebula Themes (cosmic-themes.theme-cosmic-nebula). Two more, Coca-Cola Christmas and Aurora Borealis Studio Theme, were classed as high-risk but not yet weaponised — they share the same development lineage and ship executable scaffolding a theme has no reason to include.

Socket reports that Coca-Cola Christmas and Aurora Borealis together passed 8,000 Marketplace installs, while linked Open VSX listings reached tens of thousands of downloads, including roughly 10,000 for a package called Charcoal Mint. Daily CyberSecurity notes the operators leaned on brandjacking, name-squatting against a legitimate theme and a promotional developer-community article to drive installs.

Technical details

Socket describes two different loader designs. Aurora Nocturne shipped a 59 KB obfuscated script that hid part of its payload inside invisible zero-width Unicode characters; once decoded it fetched a Windows batch file from fingercakes4sale[.]store and ran it through cmd.exe with the console window hidden. Socket links that infrastructure to the XWorm remote access trojan.

Cosmic Nebula was the more developed of the two. Socket says it decrypts an embedded stage in memory using AES-256-CBC with the hardcoded key wDO6YyTm6DL0T0zJ0SXhUql5Mo0pdlSz, then checks the system language and timezone and quietly exits on Russian-language or Russian-timezone machines. On everything else it queries the Solana address BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC and pulls the next payload URL out of a transaction memo — a dead drop the operators can update at will, without pushing a new extension version. Socket says that AES key, the Solana address and the execution model all match previously documented GlassWorm activity.

Who is affected

Anyone running the named extensions in VS Code or a compatible editor such as Cursor, on Windows in particular. Socket says GlassWorm has historically gone after credentials, session data, cryptocurrency wallets and developer authentication artefacts — the kind of material that turns one infected laptop into access to source repositories and CI pipelines. Socket adds that the Marketplace removed the reported extensions shortly after its report and listed Cosmic Nebula as malware, but that takedowns do not retroactively remove versions already installed.

What to do

Inventory installed extensions across both the Marketplace and Open VSX, and inspect the artefacts that were actually distributed rather than the public repository. Flag any theme that declares a JavaScript entry point or activates on editor startup. Hunt for cmd.exe launches from the editor, batch files written to the Windows temp folder, and unexpected queries to Solana RPC endpoints. Socket recommends re-checking extensions after each update. Treat a machine that ran either confirmed extension as compromised and rotate its credentials and tokens.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.