VDB
GCVE-110-OSM-2026-10372
GCVE-110-OSM-2026-10372
Advisory PublishedCVSS 9.6/10
TrelloBlox - Task Manager v5.7.0, published under the TrelloBlox account (unverified) on the VS Code Marketplace, is a fake Trello task-management extension sharing the same builder/operator toolkit as the ManageRBLX campaign. It auto-executes a JS -> VBS -> Batch -> PowerShell payload chain with identical persistence and anti-analysis techniques, using distinct C2 infrastructure.
Malicious payload found in: extension/src/extension.js
Extension SHA-256: 8852c7fc9c924b0664b0d6466081100011ee3cfe541549c02ef8f921b5d4c9ec
=== STAGE 1: Runtime Trigger ===
activationEvents: ["*"] forces execution on every VS Code startup.
Process chain: code.exe -> cscript.exe //nologo //e:jscript %TEMP%\nice.js
=== STAGE 2: JS Loader (javas.js) ===
Downloaded from: https://www.rogiant.com/javas.js
Staged to: %TEMP%\nice.js
=== STAGE 3: VBS Launcher (555.vbs) ===
SHA-256: be1b3c7ad7965512027915b738e63ebf4ece64e7831029c3abf408f8a19e23fd
ETag: 5c330a084cf96b4158a867950da6c661
=== STAGE 4: Batch Crypter (mami.bat) ===
Downloaded from: https://red-shape-34d7.aledreamer1234.workers.dev/mami.bat
SHA-256: 7b6cfebbe4def48437c1a1237e8d0036fbe42b817d562e37cb7283df4696a989
ETag: 01e8f1858345998085a79a4c484de58e
Staged to: %TEMP%\u640541.bat (auto-deleted after execution)
Decodes a decoy icon.png (SHA-256: afec87c0098b0a3c64216cc53c17e684a4d33614b777c695b1ab5278a4c9997d) via dual-blob carving.
=== STAGE 5: Final PowerShell Loader ===
Stage 4 loader decrypted from logo.jpg, SHA-256: 7b137a477a51785931cfb2611087af6e0d54a09c309ff377768e831450d82263
Post-loader C2: crimson-shadow-5337.aledreamer1234.workers.dev
Encoding: base64 + XOR (key "tx") -> IEX
Renamed powershell.exe dropped to: %USERPROFILE%\Downloads\svchost.exe
Persistence: C:\ProgramData\IntelDriver\wow.cmd (self-copy for relaunch), scheduled task via schtasks /create
Anti-analysis: exits if Administrator detected; VM detection (RAM < 3GB); ETW patching
Defense evasion: process injection via VirtualAlloc + WriteProcessMemory + CreateRemoteThread
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | TrelloBlox | all (affected) | — |
Browse GCVE Records
831 records in the GCVE database · Updated September 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.