VDB
GCVE-110-OSM-2026-10451
GCVE-110-OSM-2026-10451
Advisory PublishedCVSS 9.6/10
Malicious package detected. Behaviors: data exfiltration.
Microsoft removal context:
Extension ID: KsWpsClaude.wps-claude-vscode
Publisher: KsWpsClaude
Removal Date: 8/11/2026
Violation Type: malware
Removed from the VS Code Marketplace by Microsoft for violating marketplace policies.
Source: https://github.com/microsoft/vsmarketplace/blob/main/RemovedPackages.md
GitHub exposure: 10 public file(s) on GitHub reference this extension (e.g. .vscode/extensions.json recommendations, devcontainer configs, or docs). These repositories may be distributing or recommending the removed extension:
- mthcht/awesome-lists: Lists/VSCODE Extensions/feeds/ioc_all_extension_ids.txt
- mthcht/awesome-lists: Lists/VSCODE Extensions/feeds/ioc_high_risk_extension_ids.txt
- microsoft/vsmarketplace: RemovedPackages.md
- nix-community/nix4vscode: data/openvsx/data_7.json
- vsxsentry/vsxsentry.github.io: feeds/ioc_all_extension_ids.txt
- vsxsentry/vsxsentry.github.io: feeds/ioc_high_risk_extension_ids.txt
- yeeth-security/dev-guard: malicious.json
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_opencti_import.csv
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_misp_warninglist.json
- vsxsentry/vsxsentry.github.io: feeds/vsxsentry_sentinel_watchlist.csv
EXFIL
- Environment Variable Exfiltration in scripts/probe-mcp-add.mjs: "process.env, ...readCliEnv() }, stdio: ["pipe", "pipe", "pipe"], windowsHide: tr..."
- Environment Variable Exfiltration in scripts/verify-mcp-protocol.mjs: "process.env, ...readCliEnv() }, stdio: ["pipe", "pipe", "pipe"], windowsHide: tr..."
PAYLOAD FILES
scripts/probe-mcp-add.mjs (+ scripts/verify-mcp-protocol.mjs)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | KsWpsClaude.wps-claude-vscode | 0.4.6 (affected) | — |
Browse GCVE Records
831 records in the GCVE database · Updated September 3, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.