A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
…Back in August 2025, an npm supply-chain attack on Nx nicknamed s1ngularity scraped tokens from its developers en masse, in what researchers designated as the first AI-weaponized supply-chain attack…