Threat actors are publishing clean extensions that later update to depend on hidden payload packages, bypassing marketplace ...
Latest VS Code update introduces prepackaged bundles of chat customizations that can include skills, commands, agents, MCP ...