GlassWorm-linked VS Code themes (Socket, 2 Oct): 4 Marketplace + 6 Open VSX extensions — Cosmic Nebula build carries GlassWorm loader with Solana dead-drop; Coca-Cola Christmas and Aurora Borealis themes 8,000+ installs
Socket's threat research team (2 Oct 2026) found a cluster of colour-theme extensions spanning four Visual Studio Marketplace listings and six Open VSX identities, tied together by git history and shared code. The Marketplace build of Cosmic Nebula Themes contains a staged loader that decrypts embedded JavaScript with AES-256-CBC, runs it with eval(), skips Russian-language and Russian-timezone systems, and reads Solana transaction memos as a dead-drop to find its next payload server; Socket says it carries the same Solana address, AES key and execution model seen in earlier GlassWorm activity and rates it GlassWorm with high confidence. A previously removed sibling, Aurora Nocturne Night Theme, hid an obfuscated Windows downloader that wrote attacker content to a temporary batch file and ran it silently through cmd.exe. Coca-Cola Christmas and Aurora Borealis Studio Theme, still live at the time of writing with more than 8,000 combined installs, were not weaponised in the versions analysed but are rated high-risk. VS Code has no fine-grained permissions for theme extensions, so a theme can run code. Wire: Cyber Security News 5 Oct.
- Product
- Visual Studio Code extensions (Visual Studio Marketplace and Open VSX) — theme extensions
- Versions
- n/a — malicious extensions: Cosmic Nebula Themes (GlassWorm loader), Aurora Nocturne Night Theme (removed; Windows downloader), Coca-Cola Christmas and Aurora Borealis Studio Theme (high-risk, not weaponised in analysed versions); see Socket IoCs
- Exploited in Australia?
- unknown
- Patch to
- Remove the named themes, check developer machines that installed them for temporary batch-file execution and outbound Solana RPC lookups, and rotate tokens and SSH keys held on those machines. Use an extension allowlist for VS Code and Open VSX-based editors, and treat theme extensions that ship executable JavaScript as suspicious.
Primary: Socket — Pretty themes, hidden loaders: GlassWorm-linked extensions span VS Code Marketplace and Open VSX (2 Oct 2026) · Cyber Security News — GlassWorm supply chain attack uses fake VS Code themes (5 Oct 2026)
