Fake VS Code Themes Linked to GlassWorm Malware Still Available in Extension Marketplaces
A weekly threat roundup from The Hacker News highlights how attackers keep targeting developers through tools that look harmless. Socket reported finding two suspicious VS Code themes, Coca-Cola Christmas and Aurora Borealis Studio Theme, still available on the Visual Studio Marketplace. They claim to be simple colour themes, but share ties to Aurora Nocturne Night Theme, an extension that was removed earlier for hiding an obfuscated Windows downloader.
Further analysis found six extension identities in Open VSX that appear to belong to the same cluster. These include Open VSX versions of Coca-Cola Christmas and Aurora Borealis Studio Theme, as well as Cosmic Nebula Themes. The Visual Studio Marketplace build of Cosmic Nebula Themes contains a loader that decrypts and runs embedded JavaScript. It avoids systems that use Russian language or Russian time zones, and it uses Solana transaction memos to locate the infrastructure for follow-on payloads. Socket researcher Kirill Boychenko said the build contains the same Solana address, AES key and execution model previously documented in GlassWorm activity.
The wider roundup also points to malicious code in developer packages and extensions, phishing that abuses familiar online services, and a mix of complex and very basic attack methods. This summary covers only the opening of the article, not the full set of stories.