Automatic Script Execution In Visual Studio Code, (Wed, Jan 21st)
ID: 779afb5d-7ca8-5981-949b-1dd202414d94
STIX ID: report--779afb5d-7ca8-5981-949b-1dd202414d94
Feed Name: SANS ISC Diary
Threat Score
This report demonstrates how Visual Studio Code's .vscode/tasks.json "runOn: folderOpen" functionality can be abused to automatically execute Base64-encoded PowerShell payloads when a project folder is opened. The author provides a proof-of-concept JSON and decoded payload, warns that malicious VSCode extensions and similar techniques have been observed in the wild, and advises monitoring unexpected .vscode directories and inspecting tasks.json files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
