VDB
GCVE-110-OSM-2026-10487
GCVE-110-OSM-2026-10487
Advisory PublishedCVSS 9.6/10
Malicious VSCode tasks.json file in the code repository that delivers malware to the user's device when the repository is opened in Visual Studio Code.
Final payload is obfuscated JS file that delivers infostealer that exfiltrates environment variables to attacker controlled C2. Then it establishes persistent with the attacker controlled C2 hosted at 151[.]80[.]76[.]64
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
825 records in the GCVE database · Updated September 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.