GlassWorm Hackers Hid Malware in Innocent-Looking VS Code Themes That Took Orders From the Solana Blockchain
Attackers found the one kind of extension developers install without thinking twice, made it pretty, and wired it to a blockchain so it could be repointed at will.

Nobody reads the code of a color theme, which makes it a very good place to hide malware. The people behind GlassWorm noticed. Socket's Threat Research team has uncovered a cluster of VS Code themes tied to the developer-hunting campaign, four extensions on Microsoft's Visual Studio Marketplace and six extension identities on Open VSX, the open registry behind VS Code forks like Cursor and VSCodium.
A theme is supposed to be pure configuration: colors and syntax highlighting, nothing that runs. These shipped executable JavaScript anyway. Socket points out that VS Code has no granular permission controls to stop an extension's code from doing whatever it likes once installed.
GlassWorm first surfaced in October 2025 and has since crawled across developer platforms, going after credentials, session material, crypto wallets, cloud tokens, SSH keys and CI/CD secrets.
A clean repo and a booby-trapped package
The first confirmed malicious theme, Aurora Nocturne Night Theme, looked perfectly normal on GitHub. The package people actually installed was different. It carried a heavily obfuscated JavaScript file, roughly 59 KB crammed onto a single line, with its payload encoded in invisible zero-width Unicode characters. On Windows, it downloaded attacker content, saved it as a temporary command script and ran it silently, without ever flashing a command window.
The second, Cosmic Nebula Themes, was more elaborate. It activated on every VS Code session, decrypted an embedded AES-256-CBC stage and ran it through eval(). It skipped machines that looked Russian, by language or by timezone. Then it read memos attached to Solana blockchain transactions to learn where to fetch its next payload, which ran in memory with full Node.js capabilities.
That blockchain trick is the clever part. Operators can move their server just by posting a new transaction, without ever publishing a new extension version that might get flagged. The Solana address, encryption key and execution model all match earlier GlassWorm activity, which is why Socket ties the themes to the campaign with high confidence. Invisible Unicode keeps turning up as a hiding spot, too, as it did in the cloudsyncd macOS fake Zoom attack.
Two more themes with the same scaffolding
Two other themes were still live on the Marketplace while Socket investigated: Coca-Cola Christmas, borrowing a famous consumer brand, and Aurora Borealis Studio Theme, crowding an older legitimate Aurora Borealis extension. Socket found no active payload in the versions it analyzed. They are still high risk, because they ship executable code a theme has no reason to carry and share Git identities, near-identical theme files, repeated Russian-language comments and reused welcome-page code with the malicious ones.
Those two themes alone had more than 8,000 Marketplace installs. Linked Open VSX extensions racked up tens of thousands of downloads, about 10,000 for Charcoal Mint alone, though download counts do not show how many machines were actually compromised.
The operation left fingerprints. Five commits landed on 6 December 2025 within about three hours, all with the same timezone offset. On 14 December, an article promoting several of the linked themes as independent recommendations appeared from an account created that same day, which Socket reads as promotional infrastructure. Shared development evidence does not prove every publisher account belongs to one person.
Microsoft removed the reported Marketplace extensions after Socket flagged them, and says removed extensions can be blocked in the editor and force-uninstalled. Removal does not reverse anything a payload already did, and Socket says any machine where the script ran should be treated as compromised, with its credentials considered exposed. It is the same lesson developers keep relearning from attacks like Mini Shai-Hulud.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free