The researchers provided a detailed list of the malicious packages and VSCode extensions with their SHA1 hashes at the bottom of their report, to help identify and mitigate supply chain compromises.
Since vscode-java 1.2.0, it publishes platform specific versions to Microsoft VS Code marketplace. The platform versions have JRE 21 embedded in Java extension for platforms such as win32-x64, ...
The location differs depending on the value of remote.SSH.useExecServer. It will be printed in the log when starting the server. If you think a recent regression was introduced to VS Code core, using ...