
That extension that looks fine?
Attackers use this one simple trick to slip malware into your marchine.
tuckner@tuckner
Code extensions can declare an 'extensionPack' in their package.json to install other 'supporting' extensions. I detected a suspicious Python extension published today that installs another extension called my-command-pallete which was published 2 days ago.
English















