> The malware (be it a VSCode plugin, an npm package, or whatever is next)

Not the first time we've seen a developer get popped thanks to a malicious game mod either...