VDB

GCVE-110-OSM-2026-4084

GCVE-110-OSM-2026-4084
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published May 12, 2026
Attackers are using malcious visual studio code tasks.json to trigger malicious git hooks post checkout trigger. This resulting in malware delivered to user. Malicious payload trigger is the postcheckout script file located in .githooks folder. The third payload makes GET request to https://api[.]npoint[.]io/00fbe23fd7efc30639f1 . The response payload has malicious JS payload embedded in the cookie attribute in the javascript object, that is passed to eval for dynamic execution.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownall (affected)

References

Browse GCVE Records

74,947 records in the GCVE database · Updated July 28, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›