Microsoft has had a VS Code extension for a long time, and it finally came back to bite them.
Critical and high-severity vulnerabilities were found in four widely used Visual Studio Code extensions with a combined 128 million downloads, exposing developers to file theft, remote code execution, ...