A Color Theme Should Not Ship a Downloader: GlassWorm-Linked Extensions in the VS Code Marketplace and Open VSX

On 3 October 2026, Socket researchers published “Pretty Themes, Hidden Loaders”: a cluster of VS Code color-theme extensions spanning the Visual Studio Marketplace and the Open VSX registry, with a high-confidence link to GlassWorm — the developer-targeting botnet that CrowdStrike and Google moved against in May. Four extensions on the Marketplace, six extension identities on Open VSX. Two are confirmed malicious. Two more collected over 8,000 Marketplace installs before Microsoft removed the reported extensions, and the most-downloaded Open VSX member sits near 39,000 downloads.

The reason this matters beyond one more marketplace cleanup is architectural, and Socket states it plainly: a color theme only needs to change how the editor looks, yet VS Code lets themes ship JavaScript and offers no fine-grained permission controls that would confine them. That gap is what turns a theme into a loader, and it is the same gap Socket flagged in July when it mapped AI coding agents as the supply chain’s blind spot — the editor and its extensions are trusted code running on the machine that holds the keys.

The two confirmed-malicious extensions

Aurora Nocturne Night Theme is the cruder of the pair and the more instructive. The threat actor published it under the microsoft publisher identity to masquerade as a Microsoft extension, and its public repository showed ordinary theme functionality. The distributed package was a different animal: a roughly 59 KB single-line JavaScript blob using randomized names, hexadecimal escapes and zero-width Unicode encoding to hide its payload. After decoding, it contacted fingercakes4sale[.]store/dsyuC, downloaded attacker-controlled content, saved it as %TEMP%\temp_batch.cmd, and launched it through cmd.exe with the window hidden. Repository-review-as-vetting fails exactly here: the repo was clean and the package was not.

Cosmic Nebula Themes is the one that ties the cluster to GlassWorm technically rather than circumstantially. Its Marketplace build decrypted embedded JavaScript with AES-256-CBC and executed the recovered code through eval(), with later stages running in memory under Node.js capabilities. The loader checked language and timezone settings and exited on Russian-locale systems, then queried a Solana transaction memo as a dead drop to resolve follow-on payload infrastructure — a lookup that lets operators rotate delivery servers without publishing a new extension version. Socket reports the same Solana address, encryption key and execution pattern previously documented in GlassWorm activity, and attributes the analyzed build to GlassWorm with high confidence. The extension’s source repository was vovanloc2234-sudo/Cosmic-Nebula-Themes.

The high-risk middle: 8,000 installs, no payload — yet

Coca-Cola Christmas and Aurora Borealis Studio Theme collected more than 8,000 Marketplace installs between them, and the analyzed versions contained no active malicious payload. Socket classified them as high-risk anyway, and the reasoning is worth adopting as policy: both shipped unnecessary executable JavaScript, and both shared development links with the confirmed malware — overlapping Git commit identities, nearly identical theme definitions, shared welcome-page code and recurring Russian-language comments across the Coca-Cola Christmas, Aurora Nocturne and Aurora Borealis projects. An unweaponized extension that shares a codebase, a publisher graph and an update channel with a weaponized one is one publish action away from becoming the weapon. Microsoft removed the reported extensions after receiving Socket’s findings.

Open VSX deserves equal attention because it usually gets none. Socket found six cluster-linked extension identities there, including versions of Coca-Cola Christmas (~39,000 downloads) and Charcoal Mint (~10,000). Cursor, Windsurf and other VS Code forks default to Open VSX, so a cleanup on the Marketplace alone does not clear the ecosystem. And the honest caveat, stated in the secondary reporting: download totals measure potential exposure, not confirmed infections, since several analyzed versions lacked active payloads.

What to do

  • Inventory installed themes across both registries. Marketplace and Open VSX, including on machines running VS Code forks. Look for holiday-themes.theme-coca-cola-christmas, lohsebhipolg2s.theme-aurora-borealis, aurora-them-creator.theme-aurora-nocturne, cosmic-themes.theme-cosmic-nebula, charcoal-mint-studio.theme-charcoal-mint and solidity-syntax.deep-focus.
  • Inspect the package, not the repository. Check package.json, activation events, JavaScript entry points, runtime decryption, network requests and process execution in the distributed .vsix. Aurora Nocturne proved the repo can be theater.
  • If Aurora Nocturne was installed, hunt the artifacts: DNS or proxy hits to fingercakes4sale[.]store, %TEMP%\temp_batch.cmd, and cmd.exe shells parented by VS Code. Treat the host as compromised until cleared.
  • Treat executable code in a theme as a finding in itself. A color theme has no legitimate need for eval(), AES-decrypted stages, locale checks or blockchain lookups. Flag any of those in theme extensions the way you would in a document macro.
  • Watch the Solana dead-drop address BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC in transaction-memo telemetry if you have that visibility — it is the infrastructure-rotation mechanism for this cluster.

Verification note: cluster composition, dates, install and download counts, IoCs (domain, URL path, file path, hashes, Solana address, repository and extension IDs), TTPs and the Microsoft-removal outcome are drawn from Socket’s “Pretty Themes, Hidden Loaders” research of 3 October 2026 as reproduced in full, cross-checked against CyberPress’s 5 October write-up (install counts, hidden-window execution, brandjacking detail, exposure-not-infection caveat) and GBHackers’ Open VSX coverage. We did not independently detonate the packages or contact the registries before publication.

Sources: