On 5 October 2026, Socket.dev published research on a cluster of malicious VS Code extensions tied to the campaign known as GlassWorm. Four were on Microsoft's Marketplace and six identities on Open VSX.

They were colour themes.

A theme should not be able to do this

A VS Code colour theme is, by design, declarative. It is a file describing what colour each kind of token should be. Installing one should be no more dangerous than opening a settings file, because a theme has no reason to run.

These ran. The packages carried executable JavaScript alongside the styling, and nothing in the extension format or the marketplaces prevented it. A theme is allowed to ship code; it is simply unusual for one to.

That is the finding worth taking away, and it is about category rather than about these four packages. Developers apply judgement in proportion to perceived risk. A linter that reformats your files, a tool that touches git, an extension that wants network access — those get a second look. A theme gets installed because the colours looked nice. The category treated as zero-risk is the one where nobody checks, and it had no guardrail.

The obfuscation

Two of the extensions were confirmed to carry an active payload. Aurora Nocturne Night Theme was published under an identity imitating Microsoft's own naming, which is the same trick as the Custom GPT called Plus 5.6 that borrowed a subscription tier's name — a store where names are not reserved and the publisher field is not something a casual installer reads.

Its payload was compressed into roughly 59 KB on a single line, with part of it encoded using invisible Unicode characters — code points that occupy no visual space. A reviewer scrolling the file sees a long minified blob and no sign that it contains more. Manual review is not merely hard; the thing to be reviewed is not displayed.

Execution is quiet. The extension fetches attacker-controlled content, writes a temporary Windows command script, and runs it without showing a command window. From the developer's side, the editor started and the colours changed.

Why a developer machine is the target

What follows is credential theft and persistent access, and the reason that is worth more than an ordinary endpoint is what sits on a developer's machine.

Repository credentials. Cloud tokens. Package registry keys. Session cookies for the systems that build and ship software. A workstation is not the objective; it is the shortest route to the things the workstation is allowed to touch. One compromised developer is an entry point to every pipeline that trusts them, which is why this campaign has also turned up in GitHub repositories and npm packages rather than staying in one marketplace.

Install numbers give the scale without being the whole story. Two further extensions with suspicious characteristics but no active payload had more than 8,000 Marketplace installs between them, and the Open VSX listings drew tens of thousands of downloads.

Removal is not remediation

Microsoft took the reported extensions off the Marketplace after being notified. That stops new installs and does nothing else.

An extension already installed stays installed. It updates from wherever it was configured to, it runs when the editor runs, and the credentials it took are already gone. Delisting is a measure that protects people who have not been attacked yet, which is useful and is not a response for anyone who has.

This is the same gap as every package-registry takedown: the registry is the distribution channel, not the installed base. Nobody gets an alert saying the thing on your machine was removed from the shop.

What to do

  • List your installed extensions and look at the publishers, not the names. In VS Code, the command is simple and the output is short. Anything you do not recognise, or any publisher whose identity imitates a vendor, comes off today.
  • Treat themes as code, because they are. The same scrutiny you would give an extension that asks for terminal access applies to one that claims to only change colours.
  • If you find one of these, rotate first. Repository tokens, cloud credentials, npm and registry keys, and the session cookies for anything the machine was signed into.
  • Pin and review what your team installs. An allowlist of extensions is unglamorous and is the only control that works before the research gets published.

What is not established

  • How many machines ran the active payloads, as opposed to how many installs the listings recorded.
  • Who operates GlassWorm, which the research does not attribute.
  • Whether the two extensions with no active payload were staged for later use or abandoned.
  • What was taken from affected developers, and whether any of it has been used.