Researchers say the malware was in the repository for two weeks, advise precautions to defend against malicious packages.
At its core, VS Code is built on an open source project called Code OSS, published under the permissive MIT license.