Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > GlassWorm Hides Malware Inside VS Code Themes to Target Developer Workstations
GlassWorm Hides Malware Inside VS Code Themes to Target Developer Workstations
Read Time:3 Minute, 18 Second

A software supply-chain campaign known as GlassWorm is disguising malicious code as visual themes for popular development environments. Researchers identified extensions distributed through Microsoft’s Visual Studio Marketplace and Open VSX, demonstrating how a harmless-looking color scheme can become a delivery vehicle for code that executes with access to a developer workstation.

Socket researchers linked four Marketplace extensions and six Open VSX identities to the investigated cluster. Two extensions were confirmed malicious, while one carried a high-confidence technical connection to previously documented GlassWorm activity. Other linked packages did not contain an active payload in the analyzed versions, an important distinction that keeps cluster evidence separate from confirmed infection.

A theme concealed a Windows downloader

Aurora Nocturne Night Theme included heavily disguised executable JavaScript inside the distributed package even though its public repository appeared to offer ordinary theme functionality. The code was compressed into roughly 59 KB on one line and used invisible Unicode characters to hide an encoded payload. Once decoded, it fetched attacker-controlled material, wrote a temporary Windows command script and launched it without showing a command window.

The mismatch between the public repository and the extension actually delivered to users is central to the attack. A reviewer who checks only source code on GitHub can miss changes introduced during packaging. The campaign exploited the broad trust developers place in themes, which are expected to alter appearance rather than start processes or contact external infrastructure.

Encrypted loaders and a blockchain dead drop

The stronger GlassWorm connection came from Cosmic Nebula Themes. Its Marketplace build decrypted embedded JavaScript with AES-256-CBC and executed the recovered stage immediately. The loader avoided machines associated with Russian language or timezone settings, then queried transaction memos on the Solana blockchain to discover where it should retrieve another payload.

Using a blockchain address as a dead drop gives operators a flexible control mechanism. They can update the next-stage location through transaction data without publishing a new extension version or relying on one fixed command server. Retrieved JavaScript then runs in memory with access to system functions. A shared blockchain address, encryption material and execution pattern matched earlier GlassWorm reporting, supporting the attribution.

Branding and coordinated promotion built credibility

The extension cluster used familiar commercial branding and names that resembled popular themes. Coca-Cola Christmas and Aurora Borealis Studio Theme recorded more than 8,000 Marketplace installations combined, while related Open VSX entries accumulated tens of thousands of downloads. Download figures indicate exposure, not the number of infected systems, particularly because no active payload was found in the analyzed versions of those two packages.

Researchers connected projects through overlapping contributors, repeated Russian-language comments, shared welcome-page code and similar theme definitions. Several commits appeared within a narrow time window using the same timezone offset. An article created from a new publishing account also promoted linked themes as independent recommendations, which researchers assessed as part of the operation’s promotional infrastructure.

Removing the extension is only the first step

Microsoft removed reported Marketplace packages, but marketplace takedowns do not uninstall copies already present on endpoints. Organizations should inventory both registries and every compatible editor in use. Confirmed malicious identifiers include microsoftvs.microsoftvs, advertised as Aurora Nocturne Night Theme, and cosmic-themes.theme-cosmic-nebula. Defenders should also look for the temporary file temp_batch.cmd and unexpected cmd.exe /c launches from editor processes.

  • Inspect the packaged extension rather than relying only on its public repository.
  • Review activation events, bundled scripts, runtime decryption and process creation.
  • Block unnecessary network access from editors and extension hosts.
  • Reassess installed versions after updates or new threat intelligence.
  • Rotate repository, cloud and signing credentials accessible from an exposed machine.

A host that executed a downloaded command script should be treated as potentially compromised. Uninstalling the theme cannot undo credential theft, persistence or additional payloads. Developer workstations often bridge source repositories, build systems and cloud consoles, so an apparently cosmetic extension can create risk far beyond the individual endpoint.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on GlassWorm Hides Malware Inside VS Code Themes to Target Developer Workstations, use the discussion on Forum.

>> forum community

Comments

Leave a Reply