4 ms·
It’s a thing in VSCode as well/has been a thing or things similar to it : https://www.threatlocker.com/blog/malicious-vs-code-tasks-json-abuse-enables-multi-sta
by oceansweep 3mo ago
It’s a thing in VSCode as well/has been a thing or things similar to it : https://www.threatlocker.com/blog/malicious-vs-code-tasks-json-abuse-enables-multi-stage-infostealer-deployment https://www.threatlocker.com/blog/malicious-vs-code-tasks-js... (2026)
https://www.reddit.com/r/programming/comments/zes1co/visual_studio_code_remote_code_execution_advisory/ https://www.reddit.com/r/programming/comments/zes1co/visual_... (2022)
- ivirshup 3mo agoI think those are both different in that they require the user to say they trust this code. Additionally the first is arguably not a bug (the code in tasks.json will indeed run if you say you trust the project) and the second was reported and fixed within two months.
- oceansweep 3mo agoYes, my point was more so the underlying behavior of automatic execution of binaries associated with/inside of a git project exists already within vscode as a pattern, and so seeing cursor doing the same wouldn't be surprising.