Socket traces a VS Code theme cluster across marketplaces to GlassWorm-linked malware

Summary
Socket links a cluster of VS Code themes across Visual Studio Marketplace and Open VSX to two confirmed malicious extensions, including one assessed as GlassWorm with high confidence. Reported Marketplace extensions were removed.
Key points
- Socket identified a cluster spanning four Visual Studio Marketplace and six Open VSX extension identities, linked through code, Git history, publishing patterns, and other development artifacts.
- The removed Aurora Nocturne Night Theme concealed an obfuscated downloader that fetched a Windows command script and executed it from the system temporary directory.
- The Cosmic Nebula Themes Marketplace build decrypts and runs JavaScript, uses Russian-language and timezone checks, and resolves follow-on payload infrastructure through Solana transaction memos. Socket assesses it as GlassWorm with high confidence.
- Several other analyzed cluster-linked theme versions showed no active payload, but Socket considers them high-risk because they retain unnecessary executable code and share links to confirmed malicious extensions.
- Socket reported the live extensions to registry security teams; the VS Code Marketplace removed the reported extensions shortly afterward.
- Socket recommends auditing installed extensions across both registries and compatible editors, inspecting distributed packages rather than relying on public source code, and investigating hosts where confirmed malicious extensions were installed.
Article Details
- Attack Vectors
- Malicious color-theme extensions were distributed through the Visual Studio Marketplace. The broader linked cluster also had extensions in Open VSX.
- Aurora Nocturne Night Theme activated obfuscated JavaScript that downloaded an attacker-controlled Windows command script and executed it through cmd.exe.
- The analyzed Visual Studio Marketplace build of Cosmic Nebula Themes decrypted an embedded JavaScript stage at runtime. That stage used Solana transaction memos to resolve follow-on payload infrastructure and executed remotely supplied JavaScript in memory.
- Aurora Nocturne Night Theme used a Microsoft-impersonating publisher identity. The researchers also identified brandjacking or name-squatting signals in other cluster-linked themes.
- The researchers assessed a DEV Community article promoting several cluster-linked Open VSX themes as promotional infrastructure rather than an independent review.
- Defensive Notes
- Inventory developer extensions, including themes, across the Visual Studio Marketplace, Open VSX, and VS Code-compatible editors that use those registries.
- Inspect installed extension packages rather than relying on public source repositories. Review package.json, activation events, executable entrypoints, bundled JavaScript, network access, process execution, and runtime decryption.
- Re-evaluate extensions after updates and when new cluster intelligence emerges; some analyzed cluster-linked versions had no active payload but retained unnecessary executable functionality.
- For Aurora Nocturne Night Theme installations, hunt for fingercakes4sale[.]store, %TEMP%\temp_batch.cmd, and cmd.exe launched by VS Code or its extension host. Treat a host as potentially compromised if the downloaded batch file executed.
- For installations of the malicious Visual Studio Marketplace build of Cosmic Nebula Themes, investigate follow-on execution under the developer's privileges and review potentially exposed credentials and developer resources. Removing an extension does not reverse actions already performed by downloaded payloads.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | fingercakes4sale[.]store | Attacker-controlled domain contacted by the Aurora Nocturne Night Theme downloader. |
| DOMAIN | holiday-themes[.]dev | Domain listed among associated support identities for the extension cluster. |
aubineherodvulbdl@outlook[.]com | Commit identity listed as a threat-intelligence pivot linking the Aurora Nocturne Night Theme and Coca-Cola Christmas projects. | |
aurora[.]themes[.]dev@gmail[.]com | Support identity listed as a threat-intelligence pivot for the extension cluster. | |
lohsebhipolg2s@outlook[.]com | Commit identity listed as a threat-intelligence pivot linking Aurora Nocturne Night Theme to the publisher of Aurora Borealis Studio Theme. | |
support@holiday-themes[.]dev | Support identity listed as a threat-intelligence pivot for the extension cluster. | |
| SHA256 | 5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268 | SHA-256 of the obfuscated out/extension.js in Aurora Nocturne Night Theme. |
| SHA256 | 684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804 | SHA-256 of app.js in the confirmed malicious Cosmic Nebula Themes build. |
| SHA256 | a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07 | SHA-256 of the confirmed malicious Aurora Nocturne Night Theme VSIX/ZIP package. |
| SHA256 | da2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb | SHA-256 of the decrypted embedded stage in the malicious Cosmic Nebula Themes build. |
| URL | hxxps[:]//fingercakes4sale[.]store/dsyuC | Attacker-controlled payload URL used by Aurora Nocturne Night Theme. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationAurora Nocturne Night Theme concealed its downloader in obfuscated JavaScript, including a zero-width-encoded payload; Cosmic Nebula Themes embedded an encrypted JavaScript stage.T1059.003 · Windows Command ShellAurora Nocturne Night Theme executed its downloaded Windows command script through cmd.exe.T1059.007 · JavaScriptThe malicious extensions executed decoded or decrypted JavaScript, including through eval() and in-memory script execution.T1102.001 · Dead Drop ResolverThe Cosmic Nebula Themes loader read Solana transaction memos to resolve the location of follow-on payload infrastructure.T1105 · Ingress Tool TransferAurora Nocturne Night Theme downloaded attacker-controlled content to a local command script; Cosmic Nebula Themes retrieved a follow-on JavaScript stage.T1140 · Deobfuscate/Decode Files or InformationAurora Nocturne Night Theme decoded its hidden payload, while Cosmic Nebula Themes decrypted embedded JavaScript during activation.T1195.002 · Compromise Software Supply ChainMalicious extensions were published through extension marketplaces for developers to install.T1614.001 · System Language DiscoveryThe decrypted Cosmic Nebula Themes stage checked for Russian-language systems before continuing execution.
Vendors
Products
Aurora Borealis Studio Themeavailable on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme. Both present themselves as polished color themes, contain executable JavaScript despiteAurora Nocturne Night ThemeGit history and distinctive source code fingerprints connect both extensions to Aurora Nocturne Night Theme, a previously removed malicious extension whose distributed package concealed an obfuscated Windows downloader.Coca-Cola Christmassuspicious VS Code themes still available on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme. Both present themselves as polished color themes, containCosmic Nebula Themesin Open VSX, including Open VSX versions of Coca-Cola Christmas, Aurora Borealis Studio Theme, and Cosmic Nebula Themes.Open VSXSocket uncovered a theme cluster spanning four Visual Studio Marketplace and six Open VSX extensions, including two confirmed malicious extensions and a high-confidence link to GlassWorm.Visual Studio MarketplaceSocket uncovered a theme cluster spanning four Visual Studio Marketplace and six Open VSX extensions, including two confirmed malicious extensions and a high-confidence link to GlassWorm.VS CodeThe Socket Threat Research team identified two suspicious VS Code themes still available on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme. Both present