Multiple npm supply chain attacks used 50+ poisoned packages to spread IronWorm, a Rust-based stealer, and a Miasma worm ...
The agent is doing the actual work, and VS Code is just a window.
Your PC has more options than the usual household names.
Fake Claude Code installer malware used Google Ads to place spoofed AI tool pages above real documentation since March 2026.