Skip to content
Security & Trust

Color themes for VS Code are tied to a malware campaign, Socket finds

Two themes looked harmless and had no live attack. Their leftover code is the risk a later update could use.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Color themes for VS Code are tied to a malware campaign, Socket finds

AI-generated image for WebPulse. About our images

In brief
  • Socket links a cluster of VS Code themes to GlassWorm. One related theme hid a Windows downloader, and two live ones carry code a theme does not need.
  • Credential theft is one outcome Socket lists, and VS Code lacks fine permission controls. An extension that looks like decoration is a real way in.
  • Inventory the extensions on developer machines, keep an approved list, and treat any theme with a JavaScript entry point as software.

A theme is software in disguise

A color theme for a code editor sounds like decoration. It changes backgrounds and text shades. It should not run programs.

Socket's Threat Research team found themes that do more. It links them to GlassWorm. That campaign abuses extension marketplaces to steal credentials, session data and cryptocurrency wallets.

The lesson is plain. In a code editor, anything you install can carry code. A friendly name says nothing about what it does.

Developers pick these add-ons themselves. If hostile code runs, the damage can start at once.

What Socket found

Socket named two live Marketplace listings. One is Aurora Borealis Studio Theme. The other is a holiday theme called Coca-Cola Christmas.

Both pose as polished color themes. Both also contain executable JavaScript. Socket sees signs that both copy a known name or brand.

Git history and code fingerprints tie both to Aurora Nocturne Night Theme. That extension was removed earlier as malicious. Socket also found six linked extension identities on Open VSX, a separate extension registry.

Neither live theme was armed in the versions Socket analyzed. Socket still rates them high-risk. They keep code that a color theme does not need. A later update could put that code to work.

8,000+
Marketplace installs of the two live themes
Source: Socket Threat Research (October 2, 2026)
~39,000
Open VSX downloads of Coca-Cola Christmas
Source: Socket Threat Research (October 2, 2026)

How the attack works

The removed Aurora Nocturne theme shows the pattern. Its public GitHub project held a harmless-looking app.js file. The package sent to users held something else.

That package was a JavaScript file of about 59 KB, scrambled on purpose. Its payload hid in zero-width Unicode characters. These are invisible on screen.

Once decoded, the code fetched content from a domain the attacker controls. It saved that content as a batch file in the Windows temp folder. Then it ran the file silently through cmd.exe.

Anyone who read only the public repository could have missed all of this.

A second extension, Cosmic Nebula Themes, was removed by Microsoft and classed as malware. Socket studied its Marketplace build. It names a JavaScript file as its entry point and starts when the editor opens.

It decrypts a hidden stage with AES-256-CBC, a standard cipher. Then it runs the result with eval(), a command that treats text as code.

The hidden stage skips systems set to Russian language or Russian time zones. It reads Solana blockchain transaction memos to find its next servers. This trick is called a dead drop.

Socket matched the Solana address and the AES key to earlier GlassWorm activity. It assesses that build as GlassWorm with high confidence.

Why the cluster looks coordinated

Several clues tie the themes together. One Git identity wrote the full Coca-Cola Christmas history. The same identity committed the Aurora Nocturne extension.

A second identity made the first Aurora Nocturne commits. It also publishes Aurora Borealis Studio Theme.

On December 6, 2025, five relevant commits landed within about three hours. All used the same UTC-08:00 offset.

After names and colors are normalized, the two Aurora themes are nearly identical. They share the same ordered Russian-language comment markers.

Socket also cites a December 14, 2025 article on DEV Community. It posed as an independent guide to Cursor themes while promoting several of these Open VSX themes. The account behind it joined the same day.

Socket judges the post part of the operation. In its view, it gave the themes the look of a third-party recommendation.

6
Cluster-linked extension identities on Open VSX
Source: Socket Threat Research (October 2, 2026)

Who carries the risk

The cost lands on the company, not on the person who picked a color scheme. Socket says VS Code lacks granular permission controls to limit what extension code can do.

Socket lists credential theft and extra malware downloads among the outcomes of hostile code.

Dormant extensions matter too. A clean version today can turn hostile in a later update.

Socket's automated scanner labels version 1.0.2 of the Coca-Cola Christmas theme as malware. The label rests on the theme's ties to the cluster. This version holds no active payload.

Socket reported the live extensions to the security teams at both the Marketplace and Open VSX. The Marketplace team removed them soon after. The source does not say what Open VSX did.

What to ask your team

Treat editor extensions as software installs, not personal preferences. Start with these questions.

Do we know which extensions run on developer machines today? Is there an approved list? Who maintains it? Does anyone review a theme that ships a JavaScript entry point?

Do we check the published package, not only the public repository? Do we look at publisher history and brand claims before approval?

Can our endpoint tools flag a hidden process that writes a batch file to the temp folder and runs it?

If anyone installed the named extensions, review that machine and rotate the credentials stored on it. That is our recommendation, not Socket's.

A theme should change how an editor looks. It should not change what a machine does. When it can, it is software, and it needs the same scrutiny as any other.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Socket.

Share this insight