A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
… Either way, the platform telemetry could not, on its own, present an accurate assessment of the real-world exposure. It's not the first time, either A backdoored build of a hugely popular extension can't be published unless someone has the keys. …