Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX
Description
A malicious campaign involving Visual Studio Code extensions distributed via both the VS Code Marketplace and Open VSX registries has been identified. The campaign includes at least ten extensions, with two confirmed malicious themes that execute threat actor-controlled code and use sophisticated techniques such as encrypted JavaScript loaders, Russian-language gating, and Solana blockchain transaction memos for dynamic payload resolution. These extensions have been installed tens of thousands of times, posing a significant supply chain risk. Some extensions remain unweaponized but retain executable capabilities. The campaign is linked to the GlassWorm threat actor and employs brandjacking and infrastructure rotation tactics.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Security researchers identified a cluster of malicious Visual Studio Code extensions spanning the VS Code Marketplace and Open VSX registries, linked to the GlassWorm supply chain campaign. Two confirmed malicious themes include Aurora Nocturne Night Theme, which downloads and executes batch files controlled by threat actors, and Cosmic Nebula Themes, which contains a staged loader decrypting embedded JavaScript, performing Russian-language gating, and leveraging Solana blockchain transaction memos to dynamically resolve payload infrastructure. The cluster comprises at least ten extensions with over 8,000 installs on the Visual Studio Marketplace and tens of thousands on Open VSX. Git history and source code analysis confirm the connection to GlassWorm. Several extensions remain unweaponized but retain executable capabilities, posing ongoing risk. The operation uses brandjacking and sophisticated infrastructure rotation techniques to evade detection.
Potential Impact
The campaign enables threat actors to execute arbitrary code on users' systems through malicious Visual Studio Code extensions, potentially leading to credential theft and supply chain compromise. The use of dynamic payload resolution and infrastructure rotation increases the difficulty of detection and mitigation. The widespread distribution and significant installation counts amplify the risk to developers using these extensions. Although no active exploits in the wild are confirmed, the presence of executable capabilities in unweaponized extensions indicates potential for future malicious activity.
Defensive Guidance
No official patch or vendor advisory is provided for these malicious extensions. Users should immediately uninstall any suspicious or untrusted Visual Studio Code extensions, especially those identified as part of this campaign (e.g., Aurora Nocturne Night Theme, Cosmic Nebula Themes). Review installed extensions for any matching indicators such as hashes or domains associated with this campaign. Exercise caution when installing extensions from third-party registries like Open VSX. Monitor security advisories from Visual Studio Code and related marketplaces for updates. Since this is a supply chain campaign, organizations should consider implementing policies to restrict or audit extension installations.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socket.dev/blog/glassworm-vscode-themes"]
- Adversary
- GlassWorm
- Pulse Id
- 6ac07308bd5cef8481adcf61
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hasha276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07 | — | |
hash5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268 | — | |
hash684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804 | — | |
hashda2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb | — | |
hash4c4b9a3773e9dced6015a670855fd32b | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainfingercakes4sale.store | — | |
domainholiday-themes.dev | — | |
domainaurora.themes.dev | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://fingercakes4sale.store/dsyuC | — | |
urlhttps://fingercakes4sale.store/dsyuC' | — |
Threat ID: 6ac367e42cdf04f656e40b31
Added to database: 10/05/2026, 09:03:32 UTC
Last enriched: 10/05/2026, 09:34:01 UTC
Last updated: 10/05/2026, 18:48:08 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.