logo

Automatic Script Execution In Visual Studio Code, (Wed, Jan 21st)

ID: 779afb5d-7ca8-5981-949b-1dd202414d94

STIX ID: report--779afb5d-7ca8-5981-949b-1dd202414d94

Feed Name: SANS ISC Diary

Threat Score
60/100

Date Published: 2026-01-21

Date Updated: 2026-04-19

...
...

This report demonstrates how Visual Studio Code's .vscode/tasks.json "runOn: folderOpen" functionality can be abused to automatically execute Base64-encoded PowerShell payloads when a project folder is opened. The author provides a proof-of-concept JSON and decoded payload, warns that malicious VSCode extensions and similar techniques have been observed in the wild, and advises monitoring unexpected .vscode directories and inspecting tasks.json files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.