VDB

GCVE-110-OSM-2026-10372

GCVE-110-OSM-2026-10372
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 30, 2026
TrelloBlox - Task Manager v5.7.0, published under the TrelloBlox account (unverified) on the VS Code Marketplace, is a fake Trello task-management extension sharing the same builder/operator toolkit as the ManageRBLX campaign. It auto-executes a JS -> VBS -> Batch -> PowerShell payload chain with identical persistence and anti-analysis techniques, using distinct C2 infrastructure. Malicious payload found in: extension/src/extension.js Extension SHA-256: 8852c7fc9c924b0664b0d6466081100011ee3cfe541549c02ef8f921b5d4c9ec === STAGE 1: Runtime Trigger === activationEvents: ["*"] forces execution on every VS Code startup. Process chain: code.exe -> cscript.exe //nologo //e:jscript %TEMP%\nice.js === STAGE 2: JS Loader (javas.js) === Downloaded from: https://www.rogiant.com/javas.js Staged to: %TEMP%\nice.js === STAGE 3: VBS Launcher (555.vbs) === SHA-256: be1b3c7ad7965512027915b738e63ebf4ece64e7831029c3abf408f8a19e23fd ETag: 5c330a084cf96b4158a867950da6c661 === STAGE 4: Batch Crypter (mami.bat) === Downloaded from: https://red-shape-34d7.aledreamer1234.workers.dev/mami.bat SHA-256: 7b6cfebbe4def48437c1a1237e8d0036fbe42b817d562e37cb7283df4696a989 ETag: 01e8f1858345998085a79a4c484de58e Staged to: %TEMP%\u640541.bat (auto-deleted after execution) Decodes a decoy icon.png (SHA-256: afec87c0098b0a3c64216cc53c17e684a4d33614b777c695b1ab5278a4c9997d) via dual-blob carving. === STAGE 5: Final PowerShell Loader === Stage 4 loader decrypted from logo.jpg, SHA-256: 7b137a477a51785931cfb2611087af6e0d54a09c309ff377768e831450d82263 Post-loader C2: crimson-shadow-5337.aledreamer1234.workers.dev Encoding: base64 + XOR (key "tx") -> IEX Renamed powershell.exe dropped to: %USERPROFILE%\Downloads\svchost.exe Persistence: C:\ProgramData\IntelDriver\wow.cmd (self-copy for relaunch), scheduled task via schtasks /create Anti-analysis: exits if Administrator detected; VM detection (RAM < 3GB); ETW patching Defense evasion: process injection via VirtualAlloc + WriteProcessMemory + CreateRemoteThread

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownTrelloBloxall (affected)

References

vendor

Browse GCVE Records

831 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›