Open VSX fully contained the GlassWorm attacks and says it was not a self-replicating worm in the traditional sense. The GlassWorm campaign that infected VS Code extensions in the Open VSX marketplace ...
At its core, VS Code is built on an open source project called Code OSS, published under the permissive MIT license.