VDB
GCVE-110-OSM-2026-2539
GCVE-110-OSM-2026-2539
Advisory PublishedCVSS 5.4/10
Malicious VSCode tasks.json that delivers malware to the user device, when the repository is opened as Trusted workspace in VScode. In addition, attacker has second payload URL in .env file that triggers during application runtime. At the time of this report, both attacker hosted infrastructures are offline.
Malware delivered via tasks.json and malicious execution code path.
The malicious code path runs eval on the code that is fetched from the attacker controlled infrastructure.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
5.4/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Malicious package:
advisory
Browse GCVE Records
75,726 records in the GCVE database · Updated August 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.