Threat actors are publishing clean extensions that later update to depend on hidden payload packages, bypassing marketplace ...
A Hacker News commenter identifying as a VS Code team member said Workspace Trust is the intended security protection against repo-based attacks. The commenter acknowledged user experience issues and ...