Bloom Security’s “Extension Resurrection” research found that legitimate VS Code and Open VSX extension packs can reference extensions that don’t exist on the marketplace. Attackers could claim those ...