At its core, VS Code is built on an open source project called Code OSS, published under the permissive MIT license.
GlassWorm spread via 14 VS Code extensions; Solana + Google Calendar C2; stole credentials, drained 49 wallets.
The issue was complicated by inability to update Xcode, but Microsoft external support staff had the step-by-step solution, ...