GlassWorm Campaign Spreads Hidden Loaders Through VS Code Extensions
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
A cluster of malicious Visual Studio Code extensions linked to the GlassWorm threat actor was uncovered across the VS Code Marketplace and Open VSX. Disguised as polished color themes, the extensions contained obfuscated JavaScript loaders designed to retrieve secondary payloads. The campaign abuses the software supply chain to target developers and steal sensitive data from compromised environments.
Investigation
Socket researchers identified two confirmed malicious extensions and multiple high-risk, cluster-linked identities through Git history analysis and source code fingerprinting. Extensions including Aurora Nocturne Night Theme and Cosmic Nebula Themes used staged loaders, AES-256-CBC decryption, and Solana blockchain transaction memos as dead-drop resolvers for C2 infrastructure. Researchers also observed brandjacking and shared development artifacts, including Russian-language comments.
Mitigation
Organizations should inventory developer extensions installed in VS Code and similar editors, with particular attention to packages obtained from the Visual Studio Marketplace and Open VSX registries. Security reviews should examine package.json files, executable entrypoints, and unexpected network or process execution capabilities in theme extensions. Enforcing strict extension permissions and monitoring unauthorized script execution can further reduce supply chain risks.
Response
When indicators such as unexpected cmd.exe processes launched from VS Code or the presence of temp_batch.cmd are detected, immediately isolate the affected host. Investigate potentially compromised credentials, session tokens, and cryptocurrency wallets. Remove identified malicious extensions and conduct a comprehensive forensic review of the developer environment to verify that no persistent backdoors or additional payloads remain.
Attack Flow
We are still updating this part.
Detections
Suspicious Executable/Script Execution Location via [cmd.exe /C] (via cmdline)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
IOCs (HashSha256) to detect: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX Socket uncovered
IOCs (HashMd5) to detect: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX Socket uncovered
Malicious VS Code Script Execution Indicating Potential Compromise [Windows File Event]
Malicious Script Execution from VS Code Extensions [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: An adversary has successfully compromised a developer’s workstation by tricking them into installing a malicious VS Code theme extension. Upon activation, the extension executes a background process that fetches a malicious payload from a remote server (Ingress Tool Transfer). To initiate the next stage of the attack—which involves establishing persistence and downloading further tools—the extension writes a small batch script named
temp_batch.cmdto the user’s%TEMP%directory. This script is designed to execute a series of obfuscated commands to evade traditional signature-based antivirus. -
Regression Test Script:
# Simulation Script: Malicious VS Code Extension Payload Drop # Goal: Create the specific file 'temp_batch.cmd' in %TEMP% to trigger the detection rule. $tempPath = $env:TEMP $fileName = "temp_batch.cmd" $fullPath = Join-Path $tempPath $fileName Write-Host "[*] Simulating malicious VS Code extension activity..." -ForegroundColor Cyan # Create the malicious batch file $scriptContent = @" @echo off echo Simulating malicious payload execution... powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Write-Host 'Malicious Command Executed'" "@ try { Set-Content -Path $fullPath -Value $scriptContent -ErrorAction Stop Write-Host "[+] SUCCESS: Created $fullPath" -ForegroundColor Green Write-Host "[!] Monitor your SIEM/EDR for the detection alert." -ForegroundColor Yellow } catch { Write-Host "[-] FAILURE: Could not create file. Error: $($_.Exception.Message)" -ForegroundColor Red } -
Cleanup Commands:
# Cleanup Script: Remove the artifacts created during simulation $tempPath = $env:TEMP $fileName = "temp_batch.cmd" $fullPath = Join-Path $tempPath $fileName if (Test-Path $fullPath) { Remove-Item -Path $fullPath -Force Write-Host "[+] Cleanup Complete: $fullPath removed." -ForegroundColor Green } else { Write-Host "[-] Cleanup Failed: File not found." -ForegroundColor Red }