A group of Israeli researchers explored the security of the Visual Studio Code marketplace and managed to "infect" over 100 organizations by trojanizing a copy of the popular 'Dracula Official theme to include risky code. Further research into the VSCode Marketplace found thousands of extensions with millions of installs.
I don’t think I realized that the extensions could contain code since most of them are just doing syntax highlighting.
You obviously haven’t seen the platformio extension.
It’s a beast, turns VSCode into an embedded IDE and programmer for loads of different microchips