SOC Prime Bias: Critical

06 Oct 2026 14:43 UTC

GlassWorm Campaign Spreads Hidden Loaders Through VS Code Extensions

Author Photo
SOC Prime Team linkedin icon Follow
GlassWorm Campaign Spreads Hidden Loaders Through VS Code Extensions
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

A cluster of malicious Visual Studio Code extensions linked to the GlassWorm threat actor was uncovered across the VS Code Marketplace and Open VSX. Disguised as polished color themes, the extensions contained obfuscated JavaScript loaders designed to retrieve secondary payloads. The campaign abuses the software supply chain to target developers and steal sensitive data from compromised environments.

Investigation

Socket researchers identified two confirmed malicious extensions and multiple high-risk, cluster-linked identities through Git history analysis and source code fingerprinting. Extensions including Aurora Nocturne Night Theme and Cosmic Nebula Themes used staged loaders, AES-256-CBC decryption, and Solana blockchain transaction memos as dead-drop resolvers for C2 infrastructure. Researchers also observed brandjacking and shared development artifacts, including Russian-language comments.

Mitigation

Organizations should inventory developer extensions installed in VS Code and similar editors, with particular attention to packages obtained from the Visual Studio Marketplace and Open VSX registries. Security reviews should examine package.json files, executable entrypoints, and unexpected network or process execution capabilities in theme extensions. Enforcing strict extension permissions and monitoring unauthorized script execution can further reduce supply chain risks.

Response

When indicators such as unexpected cmd.exe processes launched from VS Code or the presence of temp_batch.cmd are detected, immediately isolate the affected host. Investigate potentially compromised credentials, session tokens, and cryptocurrency wallets. Remove identified malicious extensions and conduct a comprehensive forensic review of the developer environment to verify that no persistent backdoors or additional payloads remain.

Attack Flow

We are still updating this part.

Detections

Suspicious Executable/Script Execution Location via [cmd.exe /C] (via cmdline)

SOC Prime Team
06 Oct 2026

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
06 Oct 2026

IOCs (HashSha256) to detect: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX Socket uncovered

SOC Prime AI Rules
06 Oct 2026

IOCs (HashMd5) to detect: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX Socket uncovered

SOC Prime AI Rules
06 Oct 2026

Malicious VS Code Script Execution Indicating Potential Compromise [Windows File Event]

SOC Prime AI Rules
06 Oct 2026

Malicious Script Execution from VS Code Extensions [Windows Process Creation]

SOC Prime AI Rules
06 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: An adversary has successfully compromised a developer’s workstation by tricking them into installing a malicious VS Code theme extension. Upon activation, the extension executes a background process that fetches a malicious payload from a remote server (Ingress Tool Transfer). To initiate the next stage of the attack—which involves establishing persistence and downloading further tools—the extension writes a small batch script named temp_batch.cmd to the user’s %TEMP% directory. This script is designed to execute a series of obfuscated commands to evade traditional signature-based antivirus.

  • Regression Test Script:

    # Simulation Script: Malicious VS Code Extension Payload Drop
    # Goal: Create the specific file 'temp_batch.cmd' in %TEMP% to trigger the detection rule.
    
    $tempPath = $env:TEMP
    $fileName = "temp_batch.cmd"
    $fullPath = Join-Path $tempPath $fileName
    
    Write-Host "[*] Simulating malicious VS Code extension activity..." -ForegroundColor Cyan
    
    # Create the malicious batch file
    $scriptContent = @"
    @echo off
    echo Simulating malicious payload execution...
    powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Write-Host 'Malicious Command Executed'"
    "@
    
    try {
        Set-Content -Path $fullPath -Value $scriptContent -ErrorAction Stop
        Write-Host "[+] SUCCESS: Created $fullPath" -ForegroundColor Green
        Write-Host "[!] Monitor your SIEM/EDR for the detection alert." -ForegroundColor Yellow
    }
    catch {
        Write-Host "[-] FAILURE: Could not create file. Error: $($_.Exception.Message)" -ForegroundColor Red
    }
  • Cleanup Commands:

    # Cleanup Script: Remove the artifacts created during simulation
    $tempPath = $env:TEMP
    $fileName = "temp_batch.cmd"
    $fullPath = Join-Path $tempPath $fileName
    
    if (Test-Path $fullPath) {
        Remove-Item -Path $fullPath -Force
        Write-Host "[+] Cleanup Complete: $fullPath removed." -ForegroundColor Green
    } else {
        Write-Host "[-] Cleanup Failed: File not found." -ForegroundColor Red
    }