Two fake spellchecker packages on PyPI hid a Python RAT in dictionary files, activating malware on import in version 1.2.0.
Security researchers found two AI-branded VS Code extensions with 1.5M installs that covertly send source code and files to ...