VDB
GCVE-110-OSM-2026-13084
GCVE-110-OSM-2026-13084
Advisory PublishedCVSS 9.6/10
Aurora Nocturne Night Theme, published under the publisher ID 'microsoftvs' to masquerade as Microsoft, is a VS Code Marketplace theme extension confirmed malicious by Socket. It contains obfuscated JavaScript (randomized identifiers, hex escapes, zero-width Unicode payload encoding) that downloads a threat-actor-controlled file to %TEMP%\temp_batch.cmd and silently executes it via cmd.exe with window-hiding enabled.
Malicious payload found in: out/extension.js
VSIX/ZIP SHA-256: a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07
out/extension.js SHA-256: 5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268
C2 domain: fingercakes4sale.store
Payload URL: https://fingercakes4sale.store/dsyuC
Dropped file: %TEMP%\temp_batch.cmd
Behavior: Downloads attacker content via HTTPS, writes it to a .cmd file, and executes it through cmd.exe /c with windowsHide:true to suppress the console window.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | microsoftvs.microsoftvs | all (affected) | — |
Browse GCVE Records
3,105 records in the GCVE database · Updated October 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.