GitHub confirms breach of 3,800 repos via malicious VSCode extension 2 months ago
Pinning version and auditing updates might solve the problem of benign products going rogue... Can't we crowdsource, or otherwise curate the products.... I mean they (App Store, Play Store, Visual Studio Market Place, Microsoft Store,...) just don't seem to be much useful in this matter.