Hackers Distributed Malware via VS Code Themes

The GlassWorm group used malicious color themes to gain initial access to developer environments.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration depicting a sharp red geometric wedge penetrating a navy blue monolith, representing a cybersecurity breach.
The GlassWorm threat group has targeted software developers by distributing malicious JavaScript loaders disguised as popular color themes for Visual Studio Code. AI Illustration. Upload story photo >

Live Poll

Do you trust the safety of third-party extensions installed on your computer?

The GlassWorm threat group has executed a software supply chain campaign by distributing malicious loaders disguised as Visual Studio Code color themes. These extensions were hosted on both the Visual Studio Marketplace and the Open VSX Registry.

Why it matters

This campaign demonstrates an exploitation of developer-focused platforms to establish initial-access vectors into secure networks. It underscores the security risks inherent in relying on community-contributed extensions within integrated development environments.

The malicious extensions contained unnecessary executable JavaScript designed to act as an initial-access vector. This method deviates from standard theme extensions which typically contain only JSON-based metadata and CSS files.

The players

GlassWorm

A threat actor group known for executing software supply chain campaigns through malicious code distribution.

The details

The GlassWorm group embedded unauthorized JavaScript loaders within color themes designed for Visual Studio Code, a popular code editor. By packaging this code as a theme, the attackers leveraged the trust users place in the Visual Studio Marketplace and Open VSX Registry to gain execution rights on developer machines. Once installed, these extensions acted as initial-access vectors, enabling the attackers to establish a foothold in the target's development environment.

Timeline

  1. October 5, 2026: The report detailing the GlassWorm attack was published.

The Tech Race

This campaign aligns with the broader trend of supply chain attacks targeting trusted development tooling environments, similar to the 2020 SolarWinds supply chain attack. It illustrates how threat actors prioritize the compromise of software registries to bypass traditional perimeter defenses.

Developers and organizations should audit their installed VS Code extensions to identify and remove any suspicious themes or plugins. Reviewing the permissions and source of community-contributed packages is recommended to mitigate the risk of similar supply chain compromises.

The takeaway

The GlassWorm incident highlights the necessity of strictly vetting third-party extensions within integrated development environments. Organizations should monitor security advisories for the Visual Studio Marketplace to track future updates regarding compromised developer tools.

Further reading

For more on evolving threat vectors in software supply chains, visit the Cybersecurity section.

Live Poll

Do you trust the safety of third-party extensions installed on your computer?