A wave of counterfeit VS Code add-ons on Open VSX shows how naming tricks can turn a software marketplace into a developer-risk channel.
A file called sysupdate.jpeg shows why defenders should distrust extensions alone: a staged infection can turn an image-lure into trojanized remote access software.