[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxbdZ0AXmSiAN7HXNmt1SF6zSEctiWIExQ99jXI36HH4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"aedb31f1-7737-4165-981d-db23e8c789f1","malicious-vs-code-extensions-deliver-malware-loaders-via-themed-packages","85a30b25-3f8e-464b-8286-d5993d066379","Malicious VS Code Extensions Deliver Malware Loaders via Themed Packages","Threat actors linked to GlassWorm embedded malware loaders inside seemingly benign VS Code theme extensions, exploiting developer trust in popular marketplaces like Visual Studio Marketplace and Open VSX. The extensions used advanced obfuscation techniques, including decrypting and executing malicious JavaScript at runtime and leveraging Solana blockchain transaction memos for command-and-control resolution, making detection significantly harder. This attack highlights the growing risk of supply chain compromise through developer tooling ecosystems, where aesthetic or utility packages receive less scrutiny than functional libraries. With thousands of installs across both platforms, even extensions not yet 'weaponized' represent a latent threat that could be activated remotely. The incident underscores that any third-party extension, regardless of perceived harmlessness, can serve as an initial access vector.","**Immediate actions:**\n- Audit all installed VS Code extensions across your organization and remove any flagged by Socket or your threat intelligence feeds, including the identified GlassWorm-linked packages.\n- Block or restrict developer workstations from installing marketplace extensions without prior security review or an approved allowlist.\n\n**Long-term improvements:**\n- Establish a vetted internal extension registry or allowlist, requiring security approval before any VS Code extension can be installed in the development environment.\n- Integrate software composition analysis (SCA) and extension reputation scanning into CI\u002FCD pipelines and developer onboarding workflows.\n- Implement a formal third-party software vetting process that includes behavioral analysis of IDE plugins and developer tools, not just production dependencies.\n\n**Detection measures:**\n- Deploy endpoint detection tools capable of identifying suspicious JavaScript execution, encrypted payload decryption, and unusual outbound connections originating from IDE processes.\n- Monitor developer endpoints for unexpected network traffic to blockchain infrastructure (e.g., Solana RPC endpoints) or anomalous DNS lookups that could indicate C2 resolution activity.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-218 SSDF PW.4: Reuse Existing, Well-Secured Software","NIST CSF ID.SC-3: Suppliers and third-party partners are assessed","MITRE ATT&CK T1195.001: Supply Chain Compromise – Compromise Software Dependencies","MITRE ATT&CK T1071: Application Layer Protocol (C2 via blockchain)","published","2026-10-02T16:21:37.147737+00:00","2026-10-02T16:21:36.884+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fglassworm-vscode-themes?utm_medium=feed","pretty-themes-hidden-loaders-glassworm-linked-extensions-span-vs-code-marketplac-da2231","Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]