VDB
GCVE-110-OSM-2026-650
GCVE-110-OSM-2026-650
Advisory PublishedCVSS 9.6/10
GitHub repository related to the latest DPRK Contagious Interview campaign.
Payload is in the https://github.com/vb352/koinos-assessment/blob/master/.vscode/tasks.json file, which downloads and installs a second-stage loader:
https://vscode-settings-bootstrap.vercel.app/settings/mac?flag=302
https://vscode-settings-bootstrap.vercel.app/settings/linux?flag=302
https://vscode-settings-bootstrap.vercel.app/settings/windows?flag=302
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | * (affected), all (affected), all (affected), all (affected), all (affected) | — | |
| unknown | litellm | 1.82.7-1.82.8 (affected), 1.82.7-1.82.8 (affected), 1.82.7-1.82.8 (affected), 1.82.7-1.82.8 (affected), 1.82.7-1.82.8 (affected), 1.82.7-1.82.8 (affected) | — |
| unknown | all (affected) | — |
References
Malicious pypi package: litellm
advisory
Malicious package:
advisory
Malicious package:
advisory
Malicious package:
advisory
Browse GCVE Records
74,366 records in the GCVE database · Updated July 23, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.