A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
…However, because no newer version existed, auto-update never fired for infected machines, and the malicious build could remain in place for nearly a month. So you have a system that auto…
