VDB
GCVE-110-OSM-2026-13236
GCVE-110-OSM-2026-13236
Advisory PublishedCVSS 9.6/10
Git Warden confirmed this repository as malicious by static analysis of its source code. The code was read, never executed. The malicious code sits in the file .vscode/tasks.json. The code runs automatically from a Visual Studio Code task configured to trigger on folderOpen. Nothing has to be installed, built, or clicked. Opening the project folder in the editor is enough to run the attacker's command. The task fetches a remote script and pipes it straight into a shell, with a separate payload selected for macOS, Linux and Windows. It also carries a presentation block that sets reveal to never and echo to false and closes the panel afterwards, which hides the terminal so the victim never sees the command run. Suppressing output next to a fetch and pipe has no legitimate use and shows the intent is concealment. No legitimate project ships code like this. The repository was either compromised or purpose-built to deliver malware to anyone who clones or installs it. The evidence references link the exact file and line of each finding, and the payload description names every detection rule that fired, so a reviewer can open the repository and verify each one independently. Git Warden found this repository by searching GitHub for code that matches a confirmed malware signature: folderOpen curl filename:tasks.json. The delivery method, a .vscode/tasks.json task that automatically runs a remote shell command the moment the repository is opened in VS Code, matches the DPRK-attributed 'Contagious Interview' campaign, in which fake recruiters lure developers into opening a coding-task repository that silently executes a first-stage downloader. The payload is fetched from attacker-controlled infrastructure: 260120.vercel.app. This repository is one of 86 that Git Warden has confirmed as campaign GW-C-498a0aeb, which all deliver the same dropper URL shape (settings/{os}?flag=). The campaign spans 58 GitHub accounts. The other confirmed repositories are: https://github.com/123babayaga/zenithive_angular, https://github.com/adan-asim/e-commerce-admin-app-backend, https://github.com/aidevshakil055/achillcomfort_ai_repo, https://github.com/allzone-technologies/canteen-pwa, https://github.com/anshuman-jha/toku_assestment, https://github.com/arif1101/restaurant-management-server, https://github.com/arnoldesquivel/best-city436-poc, https://github.com/bhoomikamehtastartbit/reactchakraui, https://github.com/crazydev13/school-management, https://github.com/dawit212119/anbessa, https://github.com/dawit212119/bus-admin, https://github.com/dawit212119/eaglepoint-ai, https://github.com/dawit212119/ecommerce-backend, https://github.com/dawit212119/go, https://github.com/dawit212119/nextebook, https://github.com/dawit212119/wetruck, https://github.com/dishankchauhan/tech_test_pro-assignment, https://github.com/djeday123/test_repo1, https://github.com/dylanlittle/team-moshpit-project, https://github.com/eastmade/web3project-momo-token, https://github.com/eferos93/test4, https://github.com/emandeveloper/datascience, https://github.com/emigimenezj/solice2021-school-management-system, https://github.com/findusman/pos_backend, https://github.com/gauravraisharma/ticketting-system, https://github.com/hakeemsyd/fastapi-rag, https://github.com/haroldcalvo/workshop, https://github.com/helidonashabani/student-management, https://github.com/huncholane/defi_property, https://github.com/hvmgeeks/frontendengine1, and 55 more. Across the campaign the payload is served from 18 distinct hosts: 260120.vercel.app, default-configuration-sandy.vercel.app, default-configuration.vercel.app, isvalid-regions.vercel.app, vscode-bootstrapper.vercel.app, vscode-config-settings.vercel.app, vscode-extension-260120.vercel.ap, vscode-extension-260120.vercel.app, vscode-extensions-bootstrap.vercel.app, vscode-helper-132.vercel.app, vscode-helper171-ruby.vercel.app, vscode-helper171.vercel.app, vscode-load-config.vercel.app, vscode-settings-bootstrap.vercel.app, vscode-settings-config-md.vercel.app, and 3 more. Matching only one host would miss most of the operation; matching the delivery shape found all of it. Attribution: we assess this repository as PROBABLE North Korea 'Contagious Interview' activity. The evidence behind this is: (1) Delivery vector matches Contagious-Interview tradecraft: vscode-folderopen-autorun, dprk-dropper-path-shape. (2) Payload host overlaps infrastructure seen in prior DPRK/campaign repos: 260120.vercel.app.
The malicious payload sits in .vscode/tasks.json. The code runs automatically from a Visual Studio Code task configured to trigger on folderOpen. Nothing has to be installed, built, or clicked. Opening the project folder in the editor is enough to run the attacker's command. The task fetches a remote script and pipes it straight into a shell, with a separate payload selected for macOS, Linux and Windows. It also carries a presentation block that sets reveal to never and echo to false and closes the panel afterwards, which hides the terminal so the victim never sees the command run. Suppressing output next to a fetch and pipe has no legitimate use and shows the intent is concealment. Detection rules that fired in this repository: code_execution/py-dyn (1 file), install_hook/vscode-autorun (1 file).
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,142 records in the GCVE database · Updated October 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.