Skip to main content

Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX

0
Medium
Published: 10/03/2026 (10/03/2026, 03:14:16 UTC)
Source: AlienVault OTX General

Description

A malicious campaign involving Visual Studio Code extensions distributed via both the VS Code Marketplace and Open VSX registries has been identified. The campaign includes at least ten extensions, with two confirmed malicious themes that execute threat actor-controlled code and use sophisticated techniques such as encrypted JavaScript loaders, Russian-language gating, and Solana blockchain transaction memos for dynamic payload resolution. These extensions have been installed tens of thousands of times, posing a significant supply chain risk. Some extensions remain unweaponized but retain executable capabilities. The campaign is linked to the GlassWorm threat actor and employs brandjacking and infrastructure rotation tactics.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 09:34:01 UTC

Technical Analysis

Security researchers identified a cluster of malicious Visual Studio Code extensions spanning the VS Code Marketplace and Open VSX registries, linked to the GlassWorm supply chain campaign. Two confirmed malicious themes include Aurora Nocturne Night Theme, which downloads and executes batch files controlled by threat actors, and Cosmic Nebula Themes, which contains a staged loader decrypting embedded JavaScript, performing Russian-language gating, and leveraging Solana blockchain transaction memos to dynamically resolve payload infrastructure. The cluster comprises at least ten extensions with over 8,000 installs on the Visual Studio Marketplace and tens of thousands on Open VSX. Git history and source code analysis confirm the connection to GlassWorm. Several extensions remain unweaponized but retain executable capabilities, posing ongoing risk. The operation uses brandjacking and sophisticated infrastructure rotation techniques to evade detection.

Potential Impact

The campaign enables threat actors to execute arbitrary code on users' systems through malicious Visual Studio Code extensions, potentially leading to credential theft and supply chain compromise. The use of dynamic payload resolution and infrastructure rotation increases the difficulty of detection and mitigation. The widespread distribution and significant installation counts amplify the risk to developers using these extensions. Although no active exploits in the wild are confirmed, the presence of executable capabilities in unweaponized extensions indicates potential for future malicious activity.

Defensive Guidance

No official patch or vendor advisory is provided for these malicious extensions. Users should immediately uninstall any suspicious or untrusted Visual Studio Code extensions, especially those identified as part of this campaign (e.g., Aurora Nocturne Night Theme, Cosmic Nebula Themes). Review installed extensions for any matching indicators such as hashes or domains associated with this campaign. Exercise caution when installing extensions from third-party registries like Open VSX. Monitor security advisories from Visual Studio Code and related marketplaces for updates. Since this is a supply chain campaign, organizations should consider implementing policies to restrict or audit extension installations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socket.dev/blog/glassworm-vscode-themes"]
Adversary
GlassWorm
Pulse Id
6ac07308bd5cef8481adcf61

Indicators of Compromise

Hash

ValueDescriptionCopy
hasha276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07
—
hash5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268
—
hash684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804
—
hashda2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb
—
hash4c4b9a3773e9dced6015a670855fd32b
—

Domain

ValueDescriptionCopy
domainfingercakes4sale.store
—
domainholiday-themes.dev
—
domainaurora.themes.dev
—

Url

ValueDescriptionCopy
urlhttps://fingercakes4sale.store/dsyuC
—
urlhttps://fingercakes4sale.store/dsyuC'
—

Threat ID: 6ac367e42cdf04f656e40b31

Added to database: 10/05/2026, 09:03:32 UTC

Last enriched: 10/05/2026, 09:34:01 UTC

Last updated: 10/05/2026, 18:48:08 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses