If the attacker can run commands and upload binaries, it really doesn't matter what VS Code does. There are lots of commands and binaries that can open network connections.
Edit: The attacker apparently needs to control the URL and exfiltrate the activation code [0], so if they can already execute commands and open network connections, then this enables them to execute commands and open network connections. So, as mentioned by other commenters, this does sound a lot like Raymond Chen's airtight hatchway [1].
[0] https://badoption.eu/blog/2023/01/31/code_c2.html
[1] https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31...