VDB
GCVE-110-OSM-2026-1821
GCVE-110-OSM-2026-1821
Advisory PublishedCVSS 9.6/10
Malicious VSCode tasks.json file that executes on the user device, if the repository is opened as trusted workspace.
There are two types of Payload First one uses tasks.json second one is base64 encoded C2 in .env file that executes during the application runtime.
Base64 encoded C2 is 2-27-bk-9-boss-api-copy-seven[.]vercel[.]app[/]api
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Malicious package:
advisory
Browse GCVE Records
74,355 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.