# Socket Weekly: GlassWorm-Linked VS Code Themes Span Marketplace…

Canonical: https://brew.new/browse/templates/email/pt1_k97y4tvjwg3vyv52s1tps5xrps8fppa6

Brand: socket.dev
Category: welcome

![Preview of Socket Weekly: GlassWorm-Linked VS Code Themes Span Marketplace…](https://cdn.brew.new/email-preview-9b9b18ce111c42cd-tracking_r57qhsjqcemjqjfnw9g8snm00x8fpc56-1791177676821.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX

We found two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across the Marketplace and Open VSX. One decrypts an embedded payload at runtime and pulls its next-stage address from Solana transaction memos, using the same dead-drop address and AES key tied to GlassWorm. The rest of the cluster shipped executable JavaScript in extensions that were advertised as color themes.

MORE NEWS

Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

Two GitHub Actions compromised in May's Mini Shai-Hulud campaign were disabled by GitHub, then became reachable again monthls later with their release tags still pointing at the malicious code. The payload had been sitting in those tags since May, so every workflow referencing either action by tag started running it again on the next scheduled run. GitHub has since disabled both repositories.

upm Launches as a Fast, Tiny Package Manager Written in TypeScript

Everyone has been rewriting JavaScript tooling in Rust, but upm makes the case that Node.js can still hold its own. The new package manager is written in TypeScript, comes in at about 250 KB, and ranks first on cold installs in its own benchmarks. It ships with lifecycle scripts off and a one-day minimum release age by default.

MORE WORTH READING

Opt-in dist-tag permissions for npm trusted publishing

GitHub Repos Exposed 543,699 Credentials

Google's Gemini 4 Argon scores 68% on CWE-bench and 77.9% on DeepSWE, with a 1M token output limit

New AISI Report Details How GPT-6 Astra Turned CTF Challenges Into Supply Chain Attacks

Google freezes open-source bug bounty program amid flood of invalid AI slop submissions

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97y4tvjwg3vyv52s1tps5xrps8fppa6)

[Browse email designs](https://brew.new/browse/templates)
