A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
… In mid-May, three releases of durabletask, a Microsoft-maintained Python SDK, were pulled from PyPI and marked compromised, with security firm Simply Secure describing a worm-like payload built to spread across cloud infrastructure over AWS SSM and Kubernetes. …