Skip to content
GlassWorm Campaign Targets Developers with Malicious VS Code Extensions

GlassWorm Campaign Targets Developers with Malicious VS Code Extensions

First seen 6 Oct 2026, 21:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 21:29 UTC
  • •Malicious VS Code extensions linked to GlassWorm have over 8,000 installs.
  • •Extensions use obfuscated JavaScript loaders to fetch additional payloads.
  • •Organizations should review and monitor installed extensions for security.

A cluster of malicious Visual Studio Code extensions linked to the GlassWorm threat actor was uncovered, affecting thousands of developers. These extensions, disguised as color themes, contain obfuscated JavaScript loaders that can retrieve secondary payloads. The Socket Threat Research team identified two confirmed malicious extensions and several high-risk, cluster-linked identities through Git history analysis. The malicious extensions, including Coca-Cola Christmas and Aurora Borealis Studio Theme, have accumulated over 8,000 installs on the Visual Studio Marketplace. The malware uses techniques such as AES-256-CBC decryption and Solana blockchain transaction memos to communicate with command and control infrastructure. Organizations are advised to review their installed extensions, particularly those from the Visual Studio Marketplace and Open VSX. Immediate isolation of affected hosts is recommended if malicious activity is detected. The campaign exploits the software supply chain to target developers and steal sensitive data.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Malicious VS Code themes identified
Socket uncovered two malicious VS Code themes linked to GlassWorm, with thousands of installs.
Socket.Dev
2026-10-06
GlassWorm campaign reported
Socprime reported on the GlassWorm campaign, detailing the use of obfuscated JavaScript loaders.
Socprime

More articles in this cluster (2)

Common questions

Which extensions are confirmed malicious?
The confirmed malicious extensions include Coca-Cola Christmas and Aurora Borealis Studio Theme.
What should organizations do to protect themselves?
Organizations should inventory their installed VS Code extensions and monitor for any unauthorized script execution.
How widespread is the impact of this campaign?
The malicious extensions have accumulated over 8,000 installs, indicating a significant potential impact on developers.