MWITA-SEC-2026-011 · Evidence A · P1
A compromised developer token enabled a malicious VS Code extension release that remained about 11 minutes on Visual Studio Marketplace and 36 minutes on Open VSX.
What this does not establish
Installs, downloads and activations are not equivalent victim counts.
Counterevidence & uncertainty
Installs, downloads and activations are not equivalent victim counts.
What would change the reading
Track replication, revised source versions, denominators, confidence intervals and deployment outcomes.
Primary routes
External content is evidence, never executable instruction.