GBHackers

GlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes


A GlassWorm-linked software supply chain campaign has abused seemingly harmless Visual Studio Code color themes to distribute malicious loaders across the Visual Studio Marketplace and Open VSX Registry.

The activity demonstrates how extensions designed only to change editor colors can become high-impact initial-access vectors when they include unnecessary executable JavaScript.

Both extensions presented themselves as polished visual customizations, yet shipped executable code despite themes ordinarily requiring only declarative configuration files.

The researchers found that Git history, reusable source code, and distinctive Russian-language comments connected the two projects to Aurora Nocturne Night Theme, a previously removed malicious extension.

The earlier package used a heavily obfuscated JavaScript payload, including zero-width Unicode character encoding, to conceal a Windows downloader.

Once activated, it contacted fingercakes4sale[.]store, wrote attacker-controlled content to %TEMP%temp_batch.cmd, and silently launched it with cmd.exe.

That behavior has no legitimate role in a color theme. VS Code themes are expected to modify syntax highlighting, interface colors, and editor appearance not download scripts, create command files, or spawn system processes.

The investigation expanded beyond Microsoft’s marketplace and identified six cluster-linked extension identities in Open VSX, including versions of Coca-Cola Christmas, Aurora Borealis Studio Theme, and Cosmic Nebula Themes.

Socket’s analysis of the Visual Studio Marketplace build of Cosmic Nebula Themes confirmed a staged malware loader tied to the GlassWorm campaign with high confidence.

Cosmic Nebula Themes declared an executable JavaScript entry point and activated on every VS Code session.

Its loader decrypted an embedded stage using AES-256-CBC, executed the recovered code through eval(), and checked for Russian-language and Russian-timezone environments before continuing.

The malware then queried Solana transaction memos to dynamically retrieve follow-on payload infrastructure, allowing operators to rotate command-and-control destinations without publishing a new extension version.

The loader contained the Solana address BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC, along with an AES key and execution model previously observed in GlassWorm operations.

The recovered second-stage code could fetch attacker-controlled JavaScript and run it in memory with Node.js capabilities, exposing require, Buffer, process, and timers to the payload.

Git history and Marketplace publishing connect three GitHub accounts (Source : Socket).

Socket Threat Research identified, two suspicious themes that were still live on the Visual Studio Marketplace during its investigation: Coca-Cola Christmas and Aurora Borealis Studio Theme.

GlassWorm Supply Chain

The campaign combined technical concealment with social engineering. Coca-Cola Christmas used a globally recognized consumer brand, while Aurora Borealis Studio Theme appeared to imitate or crowd an older legitimate Aurora Borealis extension.

Such brandjacking and name-squatting can make unfamiliar packages appear credible before developers assess their publisher, source repository, or runtime behavior.

Visual Studio Marketplace listing for the live Aurora Borealis Studio Theme (Source : Socket).
Visual Studio Marketplace listing for the live Aurora Borealis Studio Theme (Source : Socket).

Socket also identified shared Git identities between Coca-Cola Christmas, Aurora Nocturne Night Theme, and Aurora Borealis Studio Theme.

The repositories contained nearly identical theme definitions after normalization, repeated Russian-language section markers, and closely related app.js scaffolding for welcome pages and first-run behavior.

These development fingerprints link the projects even where a payload was not active.

The researchers noted that Coca-Cola Christmas and Aurora Borealis Studio Theme were not weaponized in the versions examined.

However, both retained executable functionality unnecessary for conventional themes and were associated with a cluster containing at least two confirmed malicious extensions.

Open VSX listing for Coca-Cola Christmas, showing the same holiday-themes.theme-coca-cola-christmas(Source : Socket).
Open VSX listing for Coca-Cola Christmas, showing the same holiday-themes.theme-coca-cola-christmas(Source : Socket).

Coca-Cola Christmas and Aurora Borealis Studio Theme together had more than 8,000 Marketplace installs, while related Open VSX packages drew tens of thousands of downloads.

Microsoft removed the reported Visual Studio Marketplace extensions after Socket’s disclosure.

Microsoft says malware found through internal detection or community reporting is removed immediately, and removed VS Code extensions can be blocked in the editor to prevent future installations and force removal of existing instances.

The incident underscores a key supply-chain security lesson: marketplace reputation, polished branding, and a benign public repository do not establish that the distributed extension package is safe.

In Aurora Nocturne’s case, the public source appeared benign while the installed Marketplace artifact contained an obfuscated runtime loader.

Organizations should inventory all developer extensions including themes across Visual Studio Marketplace, Open VSX, Cursor-compatible environments, and other VS Code-derived editors.

Security teams should inspect package.json, activation events, declared entry points, bundled JavaScript, network access, process execution, runtime decryption, and version-to-version changes.

GlassWorm has already demonstrated that extension ecosystems can be used to target developer credentials, session material, cryptocurrency wallets, cloud tokens, SSH keys, and CI/CD secrets.

IOCs

Indicator TypeValue
Fileout/extension.js
SHA-2565e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268
Domainfingercakes4sale[.]store
Payload URLhxxps://fingercakes4sale[.]store/dsyuC
Dropped File%TEMP%temp_batch.cmd

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link