I remember reading a similar article here not long ago, and the attack relied on auto-loading in VSCode.

https://opensourcemalware.com/blog/latest-contagious-intervi...