VDB
GCVE-110-OSM-2026-270
GCVE-110-OSM-2026-270
Advisory PublishedCVSS 9.6/10
Malicious privilege escalation package claiming elevated execution context. Supply chain attack with MSBuild-based code execution for system compromise.
Exploits NuGet's MSBuild integration by placing malicious code in .targets files as inline tasks. When projects build, MSBuild automatically imports and executes these tasks, downloading .NET executables from throwaway GitHub repositories with embedded obfuscated command-line payloads.
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | IAmRootx | all (affected) | — |
| unknown | TheOpenAI.API | all (affected), * (affected), all (affected), * (affected), * (affected), all (affected), all (affected), all (affected) | — |
| unknown | Shade.WPF.Controls | all (affected) | — |
| unknown | randomstringgen | all (affected) | — |
| unknown | Shade.UI.WinForms | all (affected), * (affected), all (affected), all (affected), all (affected), all (affected) | — |
Aliases
References
Malicious nuget package: IAmRootx
advisory
Browse GCVE Records
75,735 records in the GCVE database · Updated August 1, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.