Extensions never had to be given unsandboxed access to everything. That's a choice that they actively made.
They probably should have some permission system where the default extension is only able to operate within the repos open at the time and has no internet access. Then you can grant internet access for the ones which genuinely need it.
The majority of VS code plugins are just syntax highlighers and linters which don't need any dangerous permissions.
Emacs, vim/nvim, intellij, etc… pretty much all vulnerable to such an attack
Reality is most devs wouldn’t be satisfied with the limitations proper sandboxing would create.