GlassWorm hides malware in VS Code theme extensions, targeting developers through Visual Studio Marketplace and Open VSX.
A serious VS Code flaw lets attackers gain persistent workstation access with one click in a malicious project, bypassing Workspace Trust via clickable editor links.