Multiple npm supply chain attacks used 50+ poisoned packages to spread IronWorm, a Rust-based stealer, and a Miasma worm ...
The agent is doing the actual work, and VS Code is just a window.
A VS Code vulnerability in GitHub.dev lets attackers steal full GitHub OAuth tokens via a single malicious link, exposing all private repositories.
Fake Claude Code installer malware used Google Ads to place spoofed AI tool pages above real documentation since March 2026.