In case you missed it, all of these malicious VS Code extensions use techniques that were responsibly disclosed to Microsoft, to which the response was:
"After careful investigation, this case has been assessed as low severity and does not meet MSRC’s bar for immediate servicing"
"Therefore, it is the user’s responsibility to ensure that they are not installing malicious extensions."
Five months later, Microsoft's own GitHub was compromised.
https://mazinahmed.net/blog/publishing-malicious-vscode-extensions/
#security #vscode #openvsx