This is frightening. I tested copilot when it first came out in beta, while I had client-owned docs, possibly containing API keys, open in the same IDE.
Maybe I rely too much on the community to red flag these things. I don't install questionable extensions. I wouldn't have tested copilot at all if it hadn't received such enthusiastic support (here, among other places). The fact that it isn't sandboxed to the document you're working on should make it an absolute malware pariah, and this is the first I'm hearing of it.