This constant stream of malicious VSCode extensions won't end anytime soon....
This batch hid its payload, a Rust-based trojan, as PNG files inside the dependencies folder
VS Code extensions contain trojan-laden fake image | ReversingLabs
RL researchers have identified 19 malicious extensions on the VS Code Marketplace — the majority containing a malicious file posing as a PNG.
ReversingLabs (www.reversinglabs.com)
