Back Socket.Dev Pretty Themes, Hidden Loaders: GlassWorm
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.
Socket uncovered a theme cluster spanning four Visual Studio Marketplace and six Open VSX extensions, including two confirmed malicious extensions and a high-confidence link to GlassWorm.
The Socket Threat Research team identified two suspicious VS Code themes still available on the Visual Studio Marketplace at the time of writing: Coca-Cola Christmas and Aurora Borealis Studio Theme . Both present themselves as polished color themes, contain executable JavaScript despite primarily providing visual customization, and exhibit signs of brandjacking or name-squatting. Theme extensions can be particularly risky because they can contain and execute malicious code, and VS Code lacks granular permission controls to restrict what that code can do.
Git history and distinctive source code fingerprints connect both extensions to Aurora Nocturne Night Theme , a previously removed malicious extension whose distributed package concealed an obfuscated Windows downloader. The malware contacted fingercakes4sale[.]store , wrote threat actor-controlled content to %TEMP%\temp_batch.cmd , and silently executed it through cmd.exe .
Expanding our hunt beyond the Visual Studio Marketplace uncovered six cluster-linked extension identities in Open VSX, including Open VSX versions of Coca-Cola Christmas , Aurora Borealis Studio Theme , and Cosmic Nebula Themes .
We analyzed the Visual Studio Marketplace build of Cosmic Nebula Themes and confirmed a staged malware loader that decrypts embedded JavaScript with AES-256-CBC, executes it through eval() , avoids Russian-language and Russian-timezone systems, and uses Solana transaction memos as a dead-drop to dynamically resolve follow-on payload infrastructure. That build contains the same Solana address, AES key, and execution model previously documented in GlassWorm activity. We assess the analyzed Marketplace build as GlassWorm with high confidence and the broader theme cluster as GlassWorm-associated.
Development evidence independently connects Cosmic Nebula Themes to the broader theme cluster. Git identities connect the Coca-Cola Christmas and Aurora Borealis Studio Theme projects, while closely related executable scaffolding and recurring Russian-language source markers extend the development linkage across the broader cluster.
The analyzed Coca-Cola Christmas and Aurora Borealis Studio Theme versions are not currently weaponized, and several additional cluster-linked Open VSX extensions that remained live during our investigation likewise did not contain active malicious payloads. We nevertheless assess these extensions as high-risk. Coca-Cola Christmas and Aurora Borealis Studio Theme alone had accumulated more than 8,000 Visual Studio Marketplace installs, while cluster-linked Open VSX extensions had also accumulated tens of thousands of downloads at the time of our investigation, including approximately 10,000 for Charcoal Mint alone. The live extensions retain executable functionality unnecessary for conventional color themes and development, publishing, or source code artifacts with a cluster that has now produced at least two confirmed malicious extensions, including the previously mentioned one linked to GlassWorm.
We reported the live extensions to both the VS Code Marketplace and Open VSX security teams. The VS Code Marketplace team removed the reported extensions shortly after receiving our report. We appreciate their quick response and both teams’ continued efforts to protect their extension ecosystems.
VS Code themes are expected to change editor appearance, such as colors, syntax highlighting, and interface styling, not execute unrelated code. Once malicious code runs, the impact can be immediate, from credential theft and secondary payload delivery to file or system modification. Even currently unweaponized extensions remain high-risk when they retain unnecessary executable capabilities that could be abused in a later update.
Our VS Code ecosystem coverage complements Marketplace protections by identifying related extensions, shared infrastructure, code reuse, version repurposing, and publishing patterns across the broader campaign.
Aurora Nocturne Had Already Been Weaponized #
Aurora Nocturne Night Theme's public project contains a benign-looking app.js implementing theme selection and welcome page functionality. The extension delivered to users executed something else.
Its manifest directed VS Code to:
out/extension.js bears little resemblance to legitimate theme code. The distributed file is a heavily obfuscated, roughly 59 KB JavaScript blob compressed into a single line, combining randomized identifiers, hexadecimal escapes, runtime string reconstruction, anti-analysis noise, and a payload encoded with zero-width Unicode characters.
A shortened excerpt from the original file is shown below, with line breaks and omissions added for readability:
Buried beneath that obfuscation is a malware loader. After decoding the zero-width payload and reconstructing the hidden strings, we recovered the following operational code. The URL is defanged for publication, and we added to explain the observed malicious behavior:
The extension downloads threat actor-controlled payload, saves it as %TEMP%\temp_batch.cmd , and executes it through cmd.exe . The windowsHide option suppresses the command window while the payload runs. A color theme has no legitimate reason to do this.
The deception also extended to the public source repository. A researcher inspecting only Aurora Nocturne Night Theme's benign-looking app.js on GitHub could miss the separate obfuscated runtime that the Marketplace extension actually executed.
Git and Source Code Tie the Projects Together #
The Git history connects the three extensions directly. The GitHub repository for Coca-Cola Christmas is owned by hakhangthu7558-sys , but its entire current Git history was authored by aubineherodvulbdl ( aubineherodvulbdl@outlook[.]com ). The same identity also committed the Aurora Nocturne Night Theme extension source.
Aurora Nocturne Night Theme’s first two commits were authored by lohsebhipolg2s ( lohsebhipolg2s@outlook[.]com ), the account that publishes Aurora Borealis Studio Theme on the VS Code Marketplace.
The timing further strengthens the relationship. On December 6, 2025, lohsebhipolg2s committed Aurora Nocturne Night Theme assets, aubineherodvulbdl added the Aurora Nocturne Night Theme extension roughly an hour later, then moved to the Coca-Cola Christmas repository and added its images and extension source. The five relevant commits occurred within roughly three hours and used the same UTC-08:00 commit offset.
Source code similarities provide another strong link: after normalizing theme-specific names and color values, the primary theme definitions in Aurora Nocturne Night Theme and Aurora Borealis Studio Theme are nearly identical, approaching 100% similarity.
Even more distinctive are developer-authored Russian-language embedded across the cluster’s theme source. Aurora Nocturne Night Theme and Aurora Borealis Studio Theme use the same ordered section markers, including ТЕРМИНАЛ (16 ANSI цветов + фон/передний план) (“Terminal, 16 ANSI colors + background/foreground”), ГРУППЫ РЕДАКТОРОВ И ВКЛАДКИ (“Editor groups and tabs”), ПОДСВЕТКА СКОБОК (“Bracket highlighting”), ОБЗОРНАЯ ЛИНЕЙКА (“Overview ruler”), and НЕДЕЙСТВИТЕЛЬНЫЙ КОД (“Invalid code”). Coca-Cola Christmas follows the same broader Russian-commented theme structure.
The projects also reuse closely related app.js scaffolding for first-run welcome pages, including the same hasShownWelcome state, scripted webviews, theme activation, and settings actions.
The Git history, near-identical theme source, and recurring developer-authored point to shared development lineage and coordinated activity across the three projects. We therefore track them as an operationally linked development cluster.
Brandjacking and Name-Squatting Signals #
Aurora Borealis Studio Theme also shows signs of brandjacking and name-squatting. An older Marketplace extension already exists as mister-gold.aurora-borealis-theme with themes named Aurora Borealis and Aurora Borealis Calm .
The later cluster-linked extension is lohsebhipolg2s.theme-aurora-borealis and exposes Aurora Borealis and Aurora Borealis Soft .
The older project has a long release history and a conventional declarative theme architecture. The later extension is published by an account directly present in the Git history of malicious Aurora Nocturne Night Theme and adds executable JavaScript.
Coca-Cola Christmas , meanwhile, uses the branding of one of the world’s most recognizable commercial brands. This branding choice makes an unfamiliar extension look familiar before a user has examined who actually published it.
The Cluster Extends Into Open VSX #
Expanding our hunt beyond the VS Code Marketplace showed that the same broader extension cluster also reached the Open VSX Registry. We identified six cluster-linked extension identities that were published there:
holiday-themes.theme-coca-cola-christmas — Coca-Cola Christmas
lohsebhipolg2s.theme-aurora-borealis — Aurora Borealis Studio Theme
aurora-them-creator.theme-aurora-nocturne — Aurora Nocturne Dreams Theme
solidity-syntax.deep-focus — Solidity syntax | Rust syntax
charcoal-mint-studio.theme-charcoal-mint — Theme Charcoal Mint Co.
cosmic-themes.theme-cosmic-nebula — Cosmic Nebula Themes
Not all six remained available at the time of writing. aurora-them-creator.theme-aurora-nocturne is distinct from the confirmed malicious microsoftvs.microsoftvs extension discussed earlier, despite the closely related Aurora Nocturne naming.
Notably, the first two are the same Coca-Cola Christmas and Aurora Borealis Studio Theme extensions central to our VS Code Marketplace investigation. Coca-Cola Christmas appears in Open VSX under the same holiday-themes.theme-coca-cola-christmas identity, while Aurora Borealis Studio Theme uses the same lohsebhipolg2s.theme-aurora-borealis identity across both registries.
A December 14, 2025 DEV Community article provides another important connection. The post presents itself as an independent guide to Cursor themes, but directly promotes Open VSX installations for Deep Focus , Aurora Borealis , Charcoal Mint , and Cosmic Nebula , while discussing Aurora Nocturne alongside Aurora Borealis . The DEV account that published the article also joined the platform on December 14, 2025, the same day the article appeared.
With our extension analysis and the broader development relationships uncovered across the cluster, we assess the article as promotional infrastructure for the operation rather than an independent theme review. It gives the extensions the appearance of third-party recommendation while directing developers to install them from Open VSX.
Cosmic Nebula Themes provides a second confirmed malicious extension within the cluster. Microsoft removed cosmic-themes.theme-cosmic-nebula from the VS Code Marketplace and classified it as malware, showing that the activity extended beyond Aurora Nocturne Night Theme and a single publisher identity.
Cosmic Nebula Themes Ties the Cluster to GlassWorm #
Our analysis of the Visual Studio Marketplace build of cosmic-themes.theme-cosmic-nebula independently confirms malicious behavior and reveals a direct technical connection to GlassWorm, a developer-targeting supply chain campaign known for abusing extension ecosystems to steal credentials, session data, cryptocurrency wallets, and developer authentication artifacts.
Although advertised as a color theme, the extension declares app.js as its executable entrypoint and activates on * . During activation, app.js decrypts an embedded JavaScript stage with AES-256-CBC and immediately executes the recovered code through eval() .
The malware loader embeds the AES key: wDO6YyTm6DL0T0zJ0SXhUql5Mo0pdlSz and the IV: 4c4b9a3773e9dced6015a670855fd32b . Static decryption recovered a second-stage loader that performs Russian-language and timezone gating, queries the Solana blockchain, dynamically resolves follow-on infrastructure from transaction memos, and executes remotely supplied JavaScript in memory.
The following excerpt is shortened from the recovered stage, with and minor normalization added by us for readability:
The Solana address BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC is a particularly strong attribution marker. We previously documented the same address as GlassWorm dead-drop infrastructure, together with the same embedded AES key, Russian-environment gating, Solana transaction-memo resolution, and staged in-memory JavaScript execution. Later GlassWorm variants retained the same underlying execution model while rotating wallets and infrastructure.
The publisher identity adds another independent link. We previously identified cosmic-themes.sql-formatter among malicious Open VSX extensions linked to GlassWorm activity. Cosmic Nebula Themes therefore shares not only GlassWorm’s technical loader fingerprints but also the cosmic-themes publisher namespace with another confirmed campaign extension.
Separately, Cosmic Nebula Themes carries the same distinctive development fingerprints found across the theme cluster, including recurring Russian-language source markers and closely related executable theme scaffolding. This independently connects the confirmed GlassWorm loader back to the Aurora Nocturne Night Theme and Coca-Cola Christmas development lineage.
The overlap is specific enough that we assess the analyzed Visual Studio Marketplace build of Cosmic Nebula Themes as GlassWorm with high confidence. Combined with the distinctive source code and development fingerprints connecting it to the Aurora Nocturne Night Theme and Coca-Cola Christmas projects, we assess the broader theme cluster as GlassWorm-associated. This does not establish that every publisher or GitHub identity is controlled by the same individual, but it places the cluster within the same operational ecosystem and tradecraft lineage.
On May 26, 2026, CrowdStrike, Google, and the Shadowserver Foundation conducted a coordinated disruption of GlassWorm, targeting multiple command and control (C2) channels used by the operation. The disruption interrupted active infrastructure, but it did not retroactively remove previously published extensions or eliminate the campaign’s established supply chain footholds.
Subsequent GlassWorm activity has continued to evolve, including new Open VSX delivery techniques, infrastructure rotation, and updated loader obfuscation. We have since documented dozens of additional malicious Open VSX extensions, reinforcing the need to hunt for older cluster members, remove remaining malicious or high-risk extensions, and re-evaluate extensions that may have appeared harmless before later weaponization.
Outlook and Recommendations #
The currently unweaponized extensions in this cluster warrant continued scrutiny. Our expanded investigation shows that the operation spans both the Visual Studio Marketplace and Open VSX and has produced at least two confirmed malicious extensions, including one we linked to GlassWorm with high confidence.
Cosmic Nebula Themes also demonstrates why defenders cannot rely solely on static infrastructure indicators or one-time extension reviews. Its loader uses Solana transaction memos as a dead-drop to dynamically resolve follow-on infrastructure, allowing the threat actor to change the -stage delivery location without republishing the extension. GlassWorm has repeatedly evolved its infrastructure and loader techniques while retaining recognizable behavioral patterns.
Defenders should inventory developer extensions (including themes) across both the Visual Studio Marketplace and Open VSX, as well as VS Code-compatible editors that consume those registries. Security review should focus on the artifact users actually install: inspect package.json , executable entrypoints, activation events, bundled JavaScript, network access, process execution, runtime decryption, and changes introduced between versions. Public source repositories should not be treated as authoritative when they differ from the distributed extension artifact.
Extensions should also be re-evaluated after updates and as new campaign intelligence emerges. High-fidelity GlassWorm signals observed in this investigation include encrypted JavaScript decrypted at runtime, Russian-language and timezone gating, Solana transaction-memo lookups, dynamically resolved second-stage URLs, the known Solana dead-drop address, ivbase64 and secretkey response headers, and execution of remotely supplied JavaScript with Node.js capabilities.
Organizations that installed Aurora Nocturne Night Theme should hunt for fingercakes4sale[.]store , %TEMP%\temp_batch.cmd , and cmd.exe launched from VS Code or its extension host. If the downloaded batch file executed, treat the host as potentially compromised.
Organizations that installed the malicious Visual Studio Marketplace version of Cosmic Nebula Themes should likewise investigate for follow-on execution under the developer’s privileges and review potentially exposed credentials and developer resources. Removing either malicious extension alone cannot reverse actions already performed by dynamically downloaded or executed payloads.
Indicators of Compromise #
Confirmed Malicious Visual Studio Marketplace Extensions #
Aurora Nocturne Night Theme ( microsoftvs.microsoftvs ) #
VSIX/ZIP SHA-256: a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07
out/extension.js SHA-256: 5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268
Domain: fingercakes4sale[.]store
Payload URL: hxxps://fingercakes4sale[.]store/dsyuC
Dropped file: %TEMP%\temp_batch.cmd
Execution: cmd.exe /c " \temp_batch.cmd"
Cosmic Nebula Themes ( cosmic-themes.theme-cosmic-nebula ) #
app.js SHA-256: 684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804
Decrypted embedded stage SHA-256: da2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb
Solana dead-drop address: BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC
AES-256-CBC key: wDO6YyTm6DL0T0zJ0SXhUql5Mo0pdlSz
AES IV: 4c4b9a3773e9dced6015a670855fd32b
Stage-response headers: ivbase64 , secretkey
Local execution marker: /init.json
GitHub repository: vovanloc2234-sudo/Cosmic-Nebula-Themes
Cluster-Linked Open VSX Extensions #
holiday-themes.theme-coca-cola-christmas
lohsebhipolg2s.theme-aurora-borealis
aurora-them-creator.theme-aurora-nocturne
solidity-syntax.deep-focus
charcoal-mint-studio.theme-charcoal-mint
cosmic-themes.theme-cosmic-nebula
The Open VSX identity aurora-them-creator.theme-aurora-nocturne is distinct from the confirmed malicious microsoftvs.microsoftvs package discussed above, despite their closely related Aurora Nocturne naming.
GitHub Accounts and Commit Identities #
aubineherodvulbdl@outlook[.]com
lohsebhipolg2s@outlook[.]com
GitHub Repositories #
aubineherodvulbdl/Aurora-Nocturne-Dreams
hakhangthu7558-sys/Coca-Cola-Christmas
lohsebhipolg2s/Aurora-Borealis-Theme
vovanloc2234-sudo/Cosmic-Nebula-Themes
Live VS Code Marketplace Cluster Pivots #
holiday-themes.theme-coca-cola-christmas
lohsebhipolg2s.theme-aurora-borealis
Associated Support Identities #
support@holiday-themes[.]dev
aurora.themes.dev@gmail[.]com
cosmic-themes.sql-formatter — previously identified by Socket as a malicious GlassWorm Open VSX extension associated with the same cosmic-themes publisher namespace.
The cluster-linked extension identities and associated accounts above are included as threat intelligence pivots. Not every analyzed extension version contained an active malicious payload. Where no payload was observed, classification reflects high-confidence association with an operational cluster that has distributed confirmed malware.
T1195.002 — Supply Chain Compromise: Compromise Software Supply Chain
T1027 — Obfuscated Files or Information
T1140 — Deobfuscate/Decode Files or Information
T1105 — Ingress Tool Transfer
T1102.001 — Web Service: Dead Drop Resolver
T1059.007 — Command and Scripting Interpreter: JavaScript
T1059.003 — Command and Scripting Interpreter: Windows Command Shell
T1614.001 — System Location Discovery: System Language Discovery
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
