Researchers warn malicious packages can harvest secrets, weaponize CI systems, and spread across projects while carrying a dormant wipe mechanism.
Critical vulnerabilities in four widely used VS Code extensions could enable file theft and remote code execution across 125M ...