GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


GlassWorm is turning developer tools into malware delivery channels, this time through extensions advertised as attractive VS Code themes.

The investigated cluster spans Visual Studio Marketplace and Open VSX, showing how appearance changes can provide cover for code that runs on developer machines. The campaign first surfaced in October 2025 and has since expanded across development platforms.

Earlier reporting on developer tools spreading GlassWorm describes credential theft and persistent access, risks that make compromised developer workstations valuable gateways into repositories, cloud environments, and other sensitive resources.

Researchers from Socket.dev identified four Marketplace extensions and six Open VSX identities linked to the theme cluster.

Socket.dev said in a report shared with Cyber Security News (CSN) that two extensions were confirmed malicious, with one showing a high-confidence technical connection to GlassWorm.

The findings distinguish confirmed malware from related extensions without active payloads. Coca-Cola Christmas and Aurora Borealis Studio Theme had more than 8,000 Marketplace installations combined.

Cluster-linked Open VSX listings attracted tens of thousands of downloads, although those totals do not establish how many users were compromised.

GlassWorm Supply Chain Attack

Aurora Nocturne Night Theme concealed a Windows downloader inside its distributed package, despite a public repository that appeared to provide theme functionality.

Its executable JavaScript was heavily disguised, compressed into roughly 59 KB on one line, and included a payload encoded with invisible Unicode characters.

After decoding the hidden instructions, the extension downloaded attacker-controlled content, saved a temporary Windows command script, and executed it without displaying a command window.

The discrepancy between public source code and the installed package explains why reviewing only a repository could miss the threat.

The disguise follows a pattern: earlier malicious icon theme extensions also combined normal visual behavior with concealed malware execution.

Historical Marketplace listing for the removed Aurora Nocturne Night Theme (Source - Socket.dev)
Historical Marketplace listing for the removed Aurora Nocturne Night Theme (Source – Socket.dev)

In the newly investigated cluster, familiar commercial branding and names copying themes helped suspicious packages appear credible before users checked their publishers.

Git histories connected several projects through shared contributors, while matching theme definitions, recurring Russian-language comments, and reused welcome-page code strengthened the development links.

Five commits on December 6, 2025, occurred within roughly three hours and used the same timezone offset. Socket also identified a December 14, 2025, article promoting several linked themes as independent recommendations. Its publishing account was created that day.

Researchers assessed the article as promotional infrastructure for the operation, rather than an unrelated review, based on the wider development evidence.

GlassWorm Defenses

Cosmic Nebula Themes provided the GlassWorm connection. Its analyzed Marketplace build decrypted embedded JavaScript using AES-256-CBC encryption and immediately executed it.

The recovered loader avoided systems matching Russian-language or Russian-timezone conditions, then consulted Solana blockchain transaction memos to locate additional payload infrastructure.

That mechanism lets attackers change the next download location without publishing a new extension version. Retrieved JavaScript then runs in memory with access to system capabilities.

The shared blockchain address, encryption key, and execution pattern matched previously documented GlassWorm activity, supporting Socket’s high-confidence attribution.

However, shared development evidence does not prove every publisher account belongs to one individual. Nor does it make every related version actively malicious.

Socket found no active payload in the analyzed Coca-Cola Christmas and Aurora Borealis Studio Theme versions, but considered their unnecessary executable functionality high-risk.

Microsoft removed the reported Marketplace extensions after notification. Defenders should inventory themes across both registries and compatible editors, because marketplace removal does not clean installed copies.

Earlier GlassWorm malicious extension updates demonstrate why security reviews must continue after an initially harmless installation. Socket recommends inspecting the packages users install, including activation settings, bundled scripts, network access, process launches, and runtime decryption.

Teams should compare versions after updates and revisit assessments when new intelligence appears, rather than treating public repositories or one-time reviews as sufficient assurance.

Organizations exposed to either confirmed malicious extension should investigate subsequent execution and potentially exposed credentials.

A host where the downloaded command script ran should be treated as potentially compromised. Removing an extension cannot undo actions performed by follow-on payloads; the indicators below support that investigation.

Indicators of compromise (IoCs):-

Type Indicator Description
Malicious extension microsoftvs.microsoftvs Confirmed malicious Marketplace package advertised as Aurora Nocturne Night Theme.
SHA-256 a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07 Aurora Nocturne Night Theme VSIX/ZIP package.
SHA-256 5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268 Aurora Nocturne Night Theme executable JavaScript.
File path out/extension.js Obfuscated executable containing the Aurora Nocturne downloader.
Domain fingercakes4sale[.]store Attacker-controlled payload delivery domain.
Payload URL hxxps://fingercakes4sale[.]store/dsyuC Download location recovered from the concealed loader.
Dropped file %TEMP%temp_batch.cmd Downloaded Windows command script.
File name temp_batch.cmd Command script basename used by the downloader.
Process cmd.exe Windows command interpreter used to execute the downloaded script.
Execution command cmd.exe /c "<TEMP_PATH>temp_batch.cmd" Execution pattern documented for Aurora Nocturne Night Theme.
Malicious extension cosmic-themes.theme-cosmic-nebula Confirmed malicious Marketplace build of Cosmic Nebula Themes; also a cluster-linked Open VSX identity.
SHA-256 684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804 Cosmic Nebula Themes executable JavaScript.
SHA-256 da2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb Decrypted embedded stage recovered from Cosmic Nebula Themes.
File name app.js Cosmic Nebula executable entrypoint; related projects also use this filename for benign-looking theme functionality.
Solana address BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC Blockchain dead-drop address used to resolve follow-on infrastructure.
AES-256-CBC key wDO6YyTm6DL0T0zJ0SXhUql5Mo0pdlSz Embedded decryption key matching previously documented GlassWorm activity.
AES initialization vector 4c4b9a3773e9dced6015a670855fd32b Initialization vector for the embedded encrypted stage.
Response header ivbase64 Header associated with decoding remotely retrieved stages.
Response header secretkey Header supplying key material for remotely retrieved stages.
Execution marker <USER_HOME>/init.json Local execution marker documented for Cosmic Nebula Themes.
Cluster-linked extension holiday-themes.theme-coca-cola-christmas Coca-Cola Christmas identity across Marketplace and Open VSX; analyzed versions lacked an active payload.
Versioned extension [email protected] Version identified through cluster attribution, not an active payload in that version.
Cluster-linked extension lohsebhipolg2s.theme-aurora-borealis Aurora Borealis Studio Theme identity across both registries; analyzed versions lacked an active payload.
Cluster-linked extension aurora-them-creator.theme-aurora-nocturne Open VSX Aurora Nocturne Dreams Theme; distinct from the confirmed malicious Aurora Nocturne Marketplace package.
Cluster-linked extension solidity-syntax.deep-focus Open VSX extension advertised as Solidity syntax and Rust syntax.
Cluster-linked extension charcoal-mint-studio.theme-charcoal-mint Open VSX Theme Charcoal Mint Co. identity.
Related malicious extension cosmic-themes.sql-formatter Previously identified GlassWorm-associated Open VSX extension sharing the Cosmic Nebula publisher namespace.
GitHub account aubineherodvulbdl Commit identity connecting Coca-Cola Christmas and Aurora Nocturne projects.
Commit email aubineherodvulbdl@outlook[.]com Email associated with the shared commit identity.
GitHub account lohsebhipolg2s Contributor to Aurora Nocturne and publisher of Aurora Borealis Studio Theme.
Commit email lohsebhipolg2s@outlook[.]com Email associated with early Aurora Nocturne commits.
GitHub account hakhangthu7558-sys Owner of the Coca-Cola Christmas repository.
GitHub account vovanloc2234-sudo Account associated with the Cosmic Nebula Themes repository.
GitHub repository aubineherodvulbdl/Aurora-Nocturne-Dreams Aurora Nocturne development repository included as an investigative pivot.
GitHub repository hakhangthu7558-sys/Coca-Cola-Christmas Coca-Cola Christmas development repository.
GitHub repository lohsebhipolg2s/Aurora-Borealis-Theme Aurora Borealis development repository.
GitHub repository vovanloc2234-sudo/Cosmic-Nebula-Themes Cosmic Nebula Themes development repository.
Support email support@holiday-themes[.]dev Associated support identity; an investigative pivot, not independent proof of compromise.
Associated domain holiday-themes[.]dev Support-related domain connected to the cluster.
Support email aurora.themes.dev@gmail[.]com Associated support identity documented by Socket.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware appeared first on Cyber Security News.