VDB
GCVE-110-OSM-2026-218
GCVE-110-OSM-2026-218
Advisory PublishedCVSS 9.6/10
Malicious Elastic Beanstalk build client for .NET. Supply chain attack targeting AWS Elastic Beanstalk deployments with MSBuild-based code execution.
Exploits NuGet's MSBuild integration by placing malicious code in .targets files as inline tasks. When projects build, MSBuild automatically imports and executes these tasks, downloading .NET executables from throwaway GitHub repositories with embedded obfuscated command-line payloads.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | makenotion-ppetest | all (affected) | — |
| unknown | OCI.DotNetSDK.File.storage | * (affected) | — |
| unknown | EBBuildClient.Net | all (affected) | — |
| unknown | OCI.DotNetSDK.Datalabeling.service | all (affected), all (affected), all (affected), all (affected), * (affected), all (affected) | — |
| unknown | OCI.DotNetSDK.Osubbillingschedule.Net | all (affected), all (affected), all (affected), all (affected), all (affected), all (affected), all (affected), all (affected) | — |
Aliases
References
Browse GCVE Records
74,355 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.