A new campaign involving 19 malicious Visual Studio Code extensions used a legitimate npm package to embed malware in ...
Researchers found malicious VS Code extensions and Go, npm, and Rust packages stealing developer data via hidden payloads and exfiltration.