Article disingenuously wraps a couple extensions that seem to be “actually” malicious (secret stealing), with one that has a lot of installs and is “HN-malicious” (collects telemetry) for a striking headline. That said, malicious code in VS Code extensions is a problem. I wonder if a GPT could be helpful here. The existing internal systems for detecting malicious code seem lacking.
"HN-malicious" Hehe. We could probably come up with a dozen similar HN specific adjectives.
Anything known to be wrong with 20/20 hindsight.