I remember reading a similar article here not long ago, and the attack relied on auto-loading in VSCode.
https://opensourcemalware.com/blog/latest-contagious-intervi...