GlassWorm Hid a Windows Downloader Inside Fake VS Code Themes on the Marketplace and Open VSX — Socket Traced the Cluster to Solana Dead-Drop Infrastructure

GlassWorm Hid a Windows Downloader Inside Fake VS Code Themes on the Marketplace and Open VSX — Socket Traced the Cluster to Solana Dead-Drop Infrastructure

GlassWorm Hid a Windows Downloader Inside Fake VS Code Themes on the Marketplace and Open VSX — Socket Traced the Cluster to Solana Dead-Drop Infrastructure

Researchers at Socket have mapped a cluster of fake theme extensions for Visual Studio Code — spread across the official Visual Studio Marketplace and the Open VSX registry — that hides a Windows downloader inside the distributed package while the public repository looks perfectly harmless. Two extensions were confirmed malicious: Aurora Nocturne Night Theme, whose package ships heavily disguised JavaScript that downloads and silently executes a command script, and Cosmic Nebula Themes, whose build decrypts an embedded stage with AES-256-CBC and runs it in memory. The Cosmic Nebula build carried a high-confidence technical connection to the GlassWorm operation.

The tradecraft is the story. Aurora Nocturne Night Theme's executable code was compressed into a single line of roughly 59 KB, with payload instructions encoded using invisible Unicode characters. After decoding, the extension fetched attacker-controlled content from fingercakes4sale[.]store, saved a temporary Windows command script (%TEMP%\temp_batch.cmd), and executed it via cmd.exe without displaying a command window. Crucially, the public source repository appeared to provide genuine theme functionality — reviewing the repo would miss the threat, because the package installed from the store was not built from it.

Cosmic Nebula Themes supplied the GlassWorm link: its analyzed build decrypted embedded JavaScript and immediately executed it, skipped systems matching Russian-language or Russian-timezone conditions, and consulted transaction memos on the Solana blockchain to locate follow-on payload infrastructure — letting operators rotate delivery points without publishing a new extension version. The shared AES key, blockchain address and execution pattern matched previously documented GlassWorm activity, supporting Socket's high-confidence attribution. The cluster spans four Marketplace extensions and six Open VSX identities in total: Coca-Cola Christmas and Aurora Borealis Studio Theme drew more than 8,000 installations combined, though Socket found no active payload in the analyzed versions — only unnecessary executable functionality it rates high-risk. Git histories tie the projects together through shared contributors, matching theme definitions, recurring Russian-language comments and five commits within roughly three hours using the same timezone offset; a December 14 article promoting the themes, published by an account created that same day, was assessed as promotional infrastructure for the operation.

Microsoft removed the reported Marketplace extensions after notification — but removal does not clean installed copies, and Open VSX listings serve the ecosystem's other editors. For development organizations the risk compounds: earlier GlassWorm developer-tool intrusions aimed at credential theft and persistent access, making a compromised developer workstation a gateway to repositories, cloud environments and secrets. The campaign first surfaced in October 2025, and the pattern echoes the npm supply-chain attack we covered in September: the store looks fine, the package is the weapon.

What Should You Do?

  1. Inventory installed themes and extensions across the dev fleet — both registries — and remove the named extensions on sight: Aurora Nocturne Night Theme and Cosmic Nebula Themes are confirmed malicious.
  2. Treat any host where Aurora Nocturne ran as potentially compromised: hunt for temp_batch.cmd, cmd.exe execution artifacts and contact with fingercakes4sale[.]store, and review exposed credentials and repository access.
  3. Inspect packages before install and after every update: activation settings, bundled scripts, network access, process launches and runtime decryption — and compare the installed package against the public repository, not the other way around.
  4. Do not treat marketplace removal as cleanup — it does not touch installed copies, and earlier GlassWorm updates turned initially harmless extensions malicious.

The WAF Angle

A theme extension with network access is an unsigned script interpreter living inside your developers' IDE — no WAF stands between it and the internet, which is why the detection layer is egress and endpoint monitoring on developer machines: a theme package reading Solana memos or fetching scripts from a no-name store domain is trivially flaggable at the network edge if anyone is watching developer workstations. This is where supply-chain defense stops being a package-registry problem and becomes a web-traffic problem — the same monitoring that catches malware delivery on any other endpoint. The unit of trust should move from "is it on the marketplace" to "what does this package do at runtime", because both confirmed-malicious extensions passed storefront review until a vendor-neutral researcher took the installed package apart.

Sources