Git history and Marketplace publishing connect three GitHub accounts across the Coca-Cola Christmas, Aurora Nocturne Night Theme, and Aurora Borealis Studio Theme projects | Image: Socket
At a Glance
| Malware family | GlassWorm loader; a separate Windows downloader |
| Threat actor | GlassWorm operators (high confidence for one extension; suspected for the wider cluster) |
| Targets | Developers using VS Code and compatible editors |
| Delivery vector | Fake or name-squatted theme extensions on the Visual Studio Marketplace and Open VSX |
| Key capabilities | Encrypted in-memory loader, Russian-system check, Solana dead-drop C2, batch file downloader |
| Scale | 8,000+ Marketplace installs for two themes; tens of thousands of Open VSX downloads (Socket figures) |
| Sources | Socket Threat Research; CrowdStrike via CyberScoop |
TL;DR
A cluster of VS Code themes hid executable code behind harmless-looking color schemes. One theme ran a Windows downloader, and another carried a GlassWorm loader. Several others had no active payload yet, but Socket still rates them high-risk.
Delivery
Themes That Should Not Run Code
A color theme only needs to change how the editor looks. However, VS Code lets themes ship JavaScript, and it offers no fine-grained permission controls. Socket warns that theme extensions “can contain and execute malicious code.”
The cluster used familiar names to win trust. “Coca-Cola Christmas” borrowed a world-famous brand. “Aurora Borealis Studio Theme” copied the name of an older, legitimate theme. Meanwhile, the removed “Aurora Nocturne Night Theme” posed under a Microsoft-style publisher identity.
A Fake Review to Drive Installs
The campaign also reached Open VSX, the registry that Cursor and other VS Code-style editors use. Socket found six linked extensions there, though not all were malicious VS Code extensions at the time. On December 14, 2025, a brand-new DEV Community account posted a “guide” to Cursor themes. It promoted four of the cluster’s Open VSX themes. Socket judges that post to be “promotional infrastructure for the operation.”
Infection Chain
Aurora Nocturne: A Hidden Windows Downloader
Aurora Nocturne activated as soon as VS Code started. Its public GitHub code looked harmless. Yet the package users installed held a 59 KB obfuscated script. Part of its payload hid inside invisible zero-width Unicode characters.
Once decoded, the script downloaded a batch file to the Windows temp folder and ran it with the command window hidden. “A color theme has no legitimate reason to do this,” Socket notes.
Cosmic Nebula: The GlassWorm Loader
The Marketplace build of Cosmic Nebula Themes went further. On launch, it decrypted an embedded script and ran it in memory. That second stage first checked the system’s language and timezone. Then it exited on Russian-language or Russian-timezone machines.
On other systems, it read a note attached to a Solana blockchain transaction. That note held the address of the next payload. As a result, the attackers can change their servers without updating the extension.
Command-and-Control and Data Theft
The Solana trick acts as a dead drop for command-and-control. The loader fetches encrypted JavaScript from the address in the memo. It then runs that code with full Node.js access, under the developer’s own permissions.
Socket did not recover the final payload in this case. However, GlassWorm is known for stealing credentials, session data, crypto wallets, and developer tokens. CrowdStrike adds that the operation also deploys a remote access tool called GlasswormRAT on Windows, macOS, and Linux.
Attribution
Socket assesses the Cosmic Nebula build as GlassWorm “with high confidence.” It shares the same Solana address, encryption key, and Russian-system check seen in earlier GlassWorm attacks. Its publisher name also matches another confirmed GlassWorm extension.
The wider cluster is a weaker link. Shared Git authors, nearly identical theme code, and Russian-language code comments connect the projects. So Socket calls the cluster “GlassWorm-associated.” It stresses this “does not establish that every publisher or GitHub identity is controlled by the same individual.”
Separately, CrowdStrike says the GlassWorm group is “likely based in Russia.” In May 2026, CrowdStrike, Google, and Shadowserver disrupted its servers. Still, Socket notes that the takedown “did not retroactively remove previously published extensions.”
Defense and Detection Guidance
Socket reported the live extensions to both registries. Microsoft removed the reported Marketplace themes shortly afterward. To check for GlassWorm VS Code themes and similar threats, teams should:
- Inventory all editor extensions, including themes, across VS Code, Cursor, and other compatible editors.
- Inspect the installed package, not just the public source repository.
- Flag themes that declare a JavaScript entry point or activate on every startup.
- Watch for editors launching cmd.exe or writing batch files to temp folders.
- Alert on developer machines querying the Solana blockchain unexpectedly.
- Recheck extensions after each update, since clean themes can turn malicious later.
If a malicious theme ran, removing it is not enough. Treat the machine as compromised, and rotate any credentials, tokens, and keys the developer could reach.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!