Multiple npm supply chain attacks used 50+ poisoned packages to spread IronWorm, a Rust-based stealer, and a Miasma worm ...
A VS Code vulnerability in GitHub.dev lets attackers steal full GitHub OAuth tokens via a single malicious link, exposing all private repositories.
Fake Claude Code installer malware used Google Ads to place spoofed AI tool pages above real documentation since March 2026.
The agent is doing the actual work, and VS Code is just a window.