A new malware campaign is A/B testing delivery effectiveness on software developers using malicious VS Code extensions.
Researchers found malicious VS Code extensions and Go, npm, and Rust packages stealing developer data via hidden payloads and exfiltration.