Researchers found malicious VS Code extensions and Go, npm, and Rust packages stealing developer data via hidden payloads and ...