A malicious VS Code extension was reportedly enough to compromise a GitHub employee device and expose internal repositories. That should make every security team ask: What’s running inside our developers’ IDEs?
github.com/DataDog/IDE-...
A VS Code/Cursor extension capable of performing realtime security monitoring from inside the IDE - DataDog/IDE-SHEPHERD-extension