A cluster of malicious Visual Studio Code extensions linked to the GlassWorm threat actor was uncovered across the VS Code Marketplace and Open VSX. Disguised as polished color themes, the extensions contained obfuscated JavaScript loaders designed to retrieve secondary payloads. The campaign abuses the software supply chain to target developers and steal sensitive data from compromised environments.
Socket researchers identified two confirmed malicious extensions and multiple high-risk, cluster-linked identities through Git history analysis and source code fingerprinting. Extensions including Aurora Nocturne Night Theme and Cosmic Nebula Themes used staged loaders, AES-256-CBC decryption, and Solana blockchain transaction memos as dead-drop resolvers for C2 infrastructure. Researchers also observed brandjacking and shared development artifacts, including Russian-language .
Organizations should inventory developer extensions installed in VS Code and similar editors, with particular attention to packages obtained from the Visual Studio Marketplace and Open VSX registries. Security reviews should examine package.json files, executable entrypoints, and unexpected network or process execution capabilities in theme extensions. Enforcing strict extension permissions and monitoring unauthorized script execution can further reduce supply chain risks.
When indicators such as unexpected cmd.exe processes launched from VS Code or the presence of temp_batch.cmd are detected, immediately isolate the affected host. Investigate potentially compromised credentials, session tokens, and cryptocurrency wallets. Remove identified malicious extensions and conduct a comprehensive forensic review of the developer environment to verify that no persistent backdoors or additional payloads remain.
Attack Narrative & Commands: An adversary has successfully compromised a developer’s workstation by tricking them into installing a malicious VS Code theme extension. Upon activation, the extension executes a background process that fetches a malicious payload from a remote server (Ingress Tool Transfer). To initiate the stage of the attack—which involves establishing persistence and downloading further tools—the extension writes a small batch script named temp_batch.cmd to the user’s %TEMP% directory. This script is designed to execute a series of obfuscated commands to evade traditional signature-based antivirus.
Attack Narrative & Commands: An adversary has successfully compromised a developer’s workstation by tricking them into installing a malicious VS Code theme extension. Upon activation, the extension executes a background process that fetches a malicious payload from a remote server (Ingress Tool Transfer). To initiate the stage of the attack—which involves establishing persistence and downloading further tools—the extension writes a small batch script named temp_batch.cmd to the user’s %TEMP% directory. This script is designed to execute a series of obfuscated commands to evade traditional signature-based antivirus.
Regression Test Script: # Simulation Script: Malicious VS Code Extension Payload Drop # Goal: Create the specific file 'temp_batch.cmd' in %TEMP% to trigger the detection rule. $tempPath = $env:TEMP $fileName = "temp_batch.cmd" $fullPath = Join-Path $tempPath $fileName Write-Host "[*] Simulating malicious VS Code extension activity..." -ForegroundColor Cyan # Create the malicious batch file $scriptContent = @" @echo off echo Simulating malicious payload execution... powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Write-Host 'Malicious Command Executed'" "@ try { Set-Content -Path $fullPath -Value $scriptContent -ErrorAction Stop Write-Host "[+] SUCCESS: Created $fullPath" -ForegroundColor Green Write-Host "[!] Monitor your SIEM/EDR for the detection alert." -ForegroundColor Yellow } catch { Write-Host "[-] FAILURE: Could not create file. Error: $($_.Exception.Message)" -ForegroundColor Red }
Regression Test Script:
Cleanup Commands: # Cleanup Script: Remove the artifacts created during simulation $tempPath = $env:TEMP $fileName = "temp_batch.cmd" $fullPath = Join-Path $tempPath $fileName if (Test-Path $fullPath) { Remove-Item -Path $fullPath -Force Write-Host "[+] Cleanup Complete: $fullPath removed." -ForegroundColor Green } else { Write-Host "[-] Cleanup Failed: File not found." -ForegroundColor Red }
Join SOC Prime's Detection as Code platform to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
