Update: Others are seeing this now: While I'm happy there's more visibility for consumers who want to call, I don't like that these likely count as a full priced click. Need to look into it more, but ...
Malicious VS Code extension ‘susvsex’ acted as ransomware and used GitHub for command control Extension appeared AI-generated, with embedded decryption keys and suspicious metadata Microsoft removed ...