A security analysis has tied a cluster of Visual Studio Code themes to the GlassWorm supply chain campaign. The operations allegedly relied on legitimate-looking themes published to Visual Studio Marketplace and Open VSX, with at least 8,000 installs for two themes on Marketplace and tens of thousands of downloads on Open VSX. The findings come from Socket Threat Research, with corroboration from CrowdStrike via CyberScoop.
The cluster appears to connect multiple GitHub accounts and projects, using familiar brand names and copycat themes to gain user trust. Some extensions initially had no active payload, but others hid executable code intended to run on startup or on launch.
Infection chains described by Socket show two main payloads. One theme, Aurora Nocturne Night Theme, carried a hidden Windows downloader: a 59 KB obfuscated script embedded in the package, decoding to download and execute a batch file in the Windows temp folder with hidden command window.
A second theme, Cosmic Nebula, deployed a GlassWorm loader that decrypts an embedded script and runs it in memory, performing system checks (language and timezone) and then referencing a Solana blockchain transaction note to obtain the next payload. This dead-drop method allows operators to switch servers without updating the extension. The loader is associated with credential and token theft capabilities, and GlassWormRAT has been noted to exist for Windows, macOS and Linux.
Defence and response guidance from Socket includes inventorying all editor extensions beyond publishers’ public repos, inspecting installed packages for JavaScript entry points, monitoring for batch file writes to temp folders, and rechecking extensions after updates. If a malicious theme ran, organisations are advised to treat devices as compromised and rotate credentials and tokens. Microsoft subsequently removed the reported Marketplace themes.