A new campaign involving 19 malicious Visual Studio Code extensions used a legitimate npm package to embed malware in ...