VDB

GCVE-110-OSM-2026-11047

GCVE-110-OSM-2026-11047
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published August 26, 2026
The VS Code extension activates an obfuscated Windows loader that establishes logon persistence and injects an embedded executable payload into trusted Windows processes. The package contains an obfuscated install script (node_modules/boardflow/install.js) that uses curl to download and execute a remote .bat file from 'erstudios.org'. This is triggered on extension activation via src/patt.js using a hidden child_process.spawn call. Related to SaassyCode campaign. Static analysis of the retrieved batch payload identified a heavily control-flow-obfuscated loader (SHA-256: 92a230214430ef703f3ceaaddd4ea84d7f722fd1e580406b90b8d69b1f8460fe). It performs a low-memory sandbox check, creates C:\\ProgramData\\IntelDriver, copies itself there as jYo.cmd, and copies the legitimate Windows PowerShell executable to %USERPROFILE%\\Downloads\\iHve.exe. It extracts an embedded encrypted PowerShell loader and a 297,571-byte shellcode payload disguised as dnjkWZp.png (SHA-256: 32e88143f982896037f04b4d2f823bafda77682654ad46706b8adcb6b7edccdd). The decrypted PowerShell stage (SHA-256: bf36c79a2d94933e233c81aa0ecf89e3f0aeea0529f49290fb493079a0a618d1) creates a hidden logon scheduled task named nvr using %APPDATA%\\nvr.xml and %LOCALAPPDATA%\\nvr.vbs. The VBS relaunches jYo.cmd invisibly. The loader injects the embedded shellcode using OpenProcess, VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. It initially targets explorer.exe and later attempts SecurityHealthSystray.exe, OneDrive.exe, sihost.exe, taskhostw.exe, and RuntimeBroker.exe. It uses the byte marker DE AD BE CA FE BA EF to detect an existing injection. It also conditionally executes a pre-existing C:\\ProgramData\\IntelDriver\\windows.ps1 stage. No direct network download, C2 destination, exfiltration behavior, or blockchain activity was recoverable from this batch payload; the executable payload is embedded locally and appears packed or otherwise opaque.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownAgendaStudios.frux-boardall (affected)

Browse GCVE Records

753 records in the GCVE database · Updated September 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›