[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:pretty-themes-hidden-loaders-glassworm-linked-extensions-span-vs-code-marketplac-mutjdyh1":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"0b02ed71-97f4-41e6-b54b-31e5b3baa5a1","Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX","pretty-themes-hidden-loaders-glassworm-linked-extensions-span-vs-code-marketplac-mutjdyh1","GlassWorm threat actors have distributed malicious VS Code extensions across Visual Studio Marketplace and Open VSX that masquerade as legitimate themes. These extensions contain malware loaders capable of executing arbitrary JavaScript and establishing C2 communications using novel techniques like Solana transaction memos. Thousands of developers have installed these extensions, creating widespread supply chain risk.","critical","advisory",[],[13,14,15,16,17],"VS Code Marketplace","Open VSX","Visual Studio Code","Coca-Cola Christmas","Aurora Borealis Studio Theme","Immediately audit your organization for installations of 'Coca-Cola Christmas', 'Aurora Borealis Studio Theme', and 'Cosmic Nebula Themes' across all developer workstations. Revoke any compromised credentials, isolate affected machines, and review VS Code extension activity logs for suspicious JavaScript execution or network connections to unfamiliar domains.",[20],"85a30b25-3f8e-464b-8286-d5993d066379",null,[23],"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fglassworm-vscode-themes?utm_medium=feed","active","2026-10-06T08:06:00.5+00:00","2026-10-04T08:06:03.273764+00:00","2026-10-04T08:06:42.991718+00:00",[29],{"id":20,"title":6,"url":23}]