Malicious Visual Studio Code extensions were discovered on the VSCode marketplace that download heavily obfuscated PowerShell payloads to target developers and cryptocurrency projects in supply chain attacks.
In a report by Reversing Labs, researchers say the malicious extensions first appeared in the VSCode marketplace in October.