VDB

GCVE-110-OSM-2026-10375

GCVE-110-OSM-2026-10375
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 13, 2026
Malicious VSCode tasks.json that delivers malware to user device. The repository is masquerading as legitimate coding assessment. At the time of this writing the C2 infrastructure is unreachable 153[.]75[.]82[.]221[:]8080 But this particular hosting provider known to host Ottercookie malware based on Intel provided by another researcher (See the attached evidence)

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

Browse GCVE Records

831 records in the GCVE database · Updated September 2, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›