The post title really buries the lede.
> You don’t even have to run a git command, just opening this directory in VSCode is enough to get infected.
The old adage that Microslop and Security in the same sentence is a contradiction in terms still applies, now with a vengeance.
Never open 3rd-party stuff with VSCode.