VYPR
supply chainPublished Oct 5, 2026· 1 source

GlassWorm Campaign Evolves, Using Fake VS Code Themes to Deliver Malware

The GlassWorm supply chain attack has expanded its reach by distributing malicious malware through fake Visual Studio Code themes on the Visual Studio Marketplace and Open VSX.

The persistent GlassWorm supply chain attack has evolved its tactics, now leveraging fake Visual Studio Code (VS Code) themes to distribute malware. Researchers have identified malicious extensions disguised as visually appealing themes, such as 'Coca-Cola Christmas' and 'Aurora Borealis Studio Theme,' being offered on both the Visual Studio Marketplace and the Open VSX registry. These deceptive extensions contain hidden executable JavaScript code designed to download and execute attacker-controlled payloads on developer machines.

The campaign, which first surfaced in October 2025, aims to compromise developer workstations, turning them into valuable entry points for accessing sensitive repositories, cloud environments, and other critical infrastructure. The malware delivered can lead to credential theft and persistent access, making it a significant threat to software development pipelines.

Researchers from Socket.dev identified four extensions on the Visual Studio Marketplace and six on Open VSX linked to this theme-based attack cluster. While two extensions were confirmed as malicious, one showed a strong technical connection to the known GlassWorm threat actor. The findings help distinguish between confirmed malware and related extensions that may not contain active payloads, though the presence of unnecessary executable functionality is flagged as a high risk.

One particularly concerning example is the 'Aurora Nocturne Night Theme' extension. Despite its public repository appearing to offer legitimate theme functionality, its distributed package concealed a Windows downloader. This downloader utilized heavily disguised and compressed JavaScript, incorporating invisible Unicode characters to further obfuscate its malicious intent. After decoding these hidden instructions, the extension would download attacker-controlled content, save a temporary Windows command script, and execute it silently without displaying a command window.

This method of hiding malicious code within seemingly benign packages highlights a critical security gap. Reviewing only the public source code of an extension might not reveal the threat, as the actual installed package can differ significantly. This tactic aligns with previous GlassWorm activities, where malicious icon theme extensions also combined normal visual behavior with concealed malware execution.

Analysis of the campaign's development history revealed shared contributors, matching theme definitions, recurring Russian-language comments, and reused welcome-page code across several projects. These links, along with synchronized commits and promotional articles published on the same day as account creation, suggest a coordinated effort to distribute these malicious themes. One specific extension, 'Cosmic Nebula Themes,' decrypted embedded JavaScript using AES-256-CBC encryption and executed it immediately. This loader also exhibited GlassWorm's characteristic behavior of avoiding systems with Russian-language or Russian-timezone settings and consulting Solana blockchain transaction memos for payload infrastructure updates.

Microsoft has since removed the identified malicious extensions from the Visual Studio Marketplace. However, defenders are urged to inventory themes across both registries and compatible editors, as marketplace removal does not automatically clean installed copies on user machines. The evolution of GlassWorm's tactics underscores the need for continuous security vigilance, including inspecting installed packages for suspicious scripts, network access, and runtime behavior, and comparing versions after updates.

Synthesized by Vypr AI
GlassWorm Campaign Evolves, Using Fake VS Code Themes to Deliver Malware · VYPR