Socket traces a VS Code theme cluster across marketplaces to GlassWorm-linked malware

· Original article ↗

Summary

Socket links a cluster of VS Code themes across Visual Studio Marketplace and Open VSX to two confirmed malicious extensions, including one assessed as GlassWorm with high confidence. Reported Marketplace extensions were removed.

Key points

  • Socket identified a cluster spanning four Visual Studio Marketplace and six Open VSX extension identities, linked through code, Git history, publishing patterns, and other development artifacts.
  • The removed Aurora Nocturne Night Theme concealed an obfuscated downloader that fetched a Windows command script and executed it from the system temporary directory.
  • The Cosmic Nebula Themes Marketplace build decrypts and runs JavaScript, uses Russian-language and timezone checks, and resolves follow-on payload infrastructure through Solana transaction memos. Socket assesses it as GlassWorm with high confidence.
  • Several other analyzed cluster-linked theme versions showed no active payload, but Socket considers them high-risk because they retain unnecessary executable code and share links to confirmed malicious extensions.
  • Socket reported the live extensions to registry security teams; the VS Code Marketplace removed the reported extensions shortly afterward.
  • Socket recommends auditing installed extensions across both registries and compatible editors, inspecting distributed packages rather than relying on public source code, and investigating hosts where confirmed malicious extensions were installed.

Article Details

Attack Vectors
  • Malicious color-theme extensions were distributed through the Visual Studio Marketplace. The broader linked cluster also had extensions in Open VSX.
  • Aurora Nocturne Night Theme activated obfuscated JavaScript that downloaded an attacker-controlled Windows command script and executed it through cmd.exe.
  • The analyzed Visual Studio Marketplace build of Cosmic Nebula Themes decrypted an embedded JavaScript stage at runtime. That stage used Solana transaction memos to resolve follow-on payload infrastructure and executed remotely supplied JavaScript in memory.
  • Aurora Nocturne Night Theme used a Microsoft-impersonating publisher identity. The researchers also identified brandjacking or name-squatting signals in other cluster-linked themes.
  • The researchers assessed a DEV Community article promoting several cluster-linked Open VSX themes as promotional infrastructure rather than an independent review.
Defensive Notes
  • Inventory developer extensions, including themes, across the Visual Studio Marketplace, Open VSX, and VS Code-compatible editors that use those registries.
  • Inspect installed extension packages rather than relying on public source repositories. Review package.json, activation events, executable entrypoints, bundled JavaScript, network access, process execution, and runtime decryption.
  • Re-evaluate extensions after updates and when new cluster intelligence emerges; some analyzed cluster-linked versions had no active payload but retained unnecessary executable functionality.
  • For Aurora Nocturne Night Theme installations, hunt for fingercakes4sale[.]store, %TEMP%\temp_batch.cmd, and cmd.exe launched by VS Code or its extension host. Treat a host as potentially compromised if the downloaded batch file executed.
  • For installations of the malicious Visual Studio Marketplace build of Cosmic Nebula Themes, investigate follow-on execution under the developer's privileges and review potentially exposed credentials and developer resources. Removing an extension does not reverse actions already performed by downloaded payloads.

Indicators of compromise

TypeIndicatorContext
DOMAINfingercakes4sale[.]storeAttacker-controlled domain contacted by the Aurora Nocturne Night Theme downloader.
DOMAINholiday-themes[.]devDomain listed among associated support identities for the extension cluster.
EMAILaubineherodvulbdl@outlook[.]comCommit identity listed as a threat-intelligence pivot linking the Aurora Nocturne Night Theme and Coca-Cola Christmas projects.
EMAILaurora[.]themes[.]dev@gmail[.]comSupport identity listed as a threat-intelligence pivot for the extension cluster.
EMAILlohsebhipolg2s@outlook[.]comCommit identity listed as a threat-intelligence pivot linking Aurora Nocturne Night Theme to the publisher of Aurora Borealis Studio Theme.
EMAILsupport@holiday-themes[.]devSupport identity listed as a threat-intelligence pivot for the extension cluster.
SHA2565e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268SHA-256 of the obfuscated out/extension.js in Aurora Nocturne Night Theme.
SHA256684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804SHA-256 of app.js in the confirmed malicious Cosmic Nebula Themes build.
SHA256a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07SHA-256 of the confirmed malicious Aurora Nocturne Night Theme VSIX/ZIP package.
SHA256da2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bbSHA-256 of the decrypted embedded stage in the malicious Cosmic Nebula Themes build.
URLhxxps[:]//fingercakes4sale[.]store/dsyuCAttacker-controlled payload URL used by Aurora Nocturne Night Theme.

MITRE ATT&CK

Vendors

Products

Tools

Industries

Related Articles