Hackers Distributed Malicious Visual Studio Code Themes

The GlassWorm group used compromised code themes to embed malicious loaders within developer environments.

Updated on Oct. 5, 2026 in Cybersecurity

Isometric editorial illustration showing a cluster of modular hardware blocks and fiber-optic lines representing digital software supply chain vulnerability.
The GlassWorm group used malicious color themes on the Visual Studio Marketplace to distribute malware, exposing developers to supply chain security risks. AI Illustration. Upload story photo >

Live Poll

Do you trust the safety of third-party extensions installed on your computer?

Hackers identified as the GlassWorm group successfully distributed malicious loaders through popular color themes on the Visual Studio Marketplace and Open VSX Registry. These extensions acted as initial-access vectors by embedding unnecessary executable JavaScript code.

Why it matters

The campaign highlights significant security vulnerabilities in software supply chains that rely on third-party marketplace extensions. Developers who download themes for customization may inadvertently grant attackers a bridge into their local machines.

The malicious extensions contained unnecessary executable JavaScript designed to function as an initial-access loader. This specific code allowed the GlassWorm group to compromise developer environments through seemingly benign visual theme updates.

The players

GlassWorm

GlassWorm is a hacking collective that specializes in software supply chain attacks.

Visual Studio Marketplace

Visual Studio Marketplace is an official platform that hosts extensions and themes for developers using Visual Studio Code.

Open VSX Registry

Open VSX Registry is an open-source alternative to the primary Visual Studio Marketplace for distributing extensions.

The details

The GlassWorm group executed a software supply chain campaign by embedding malicious loaders directly inside Visual Studio Code color themes. By hiding these scripts within the themes, the attackers bypassed typical user scrutiny, effectively using the platforms as distribution hubs for their initial-access vectors.

Timeline

  1. The report detailing the GlassWorm attack was published on October 5, 2026.

The Tech Race

The incident demonstrates a growing reliance on third-party marketplaces and the subsequent rise in supply chain attacks targeting developer tooling. As platforms like the Visual Studio Marketplace evolve, this shift marks a move toward tighter vetting requirements to prevent the unauthorized use of the Visual Studio Code extension architecture.

Developers should audit their installed Visual Studio Code themes and remove any extensions that are not verified or originate from unknown publishers. Maintaining a strict security hygiene regarding extensions is essential to prevent unauthorized remote access to your local machine.

The takeaway

Developers should treat every marketplace extension, even those intended only for aesthetic customization, as potential code execution risks. Always verify the publisher and review requested permissions before installing new themes in your code editor.

Further reading

For more information on securing development environments, see our full coverage of Cybersecurity.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you trust the safety of third-party extensions installed on your computer?