HackerFeeds

CyberSecurity News

Tell HN: VSCode/Cursor Exploit Actively Used by Scammers

Hacker News
· October 2, 2026

AI summary

A scammer attempted to exploit a vulnerability in VSCode by asking a potential technical consultant to clone a public repository and open it in VSCode. The repository contained a task in `tasks.json` that would auto-run and harvest credentials from `process.env`, sending them to a remote server. The consultant became suspicious and refused to open the repository, after which the scammer disconnected and removed their LinkedIn presence. The scammer's method relied on VSCode's ability to automatically run tasks listed in `tasks.json`. The consultant was able to identify the exploit without executing it. The scammer's goal was to steal credentials using this technique.

Read the full article at Hacker Newsnews.ycombinator.com/item?id=49931454

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to Hacker News.