For more than a year, a self-propagating worm rode VS Code extensions, npm packages, and stolen developer credentials through ...