Evil-twin Open VSX extension install from known malicious namespace

This rule detects the installation of malicious VS Code extensions by monitoring file system writes within common VS Code and VS Code Server extension directories. It specifically alerts on a predefined list of extension namespaces associated with a known malicious coordinated campaign that impersonated legitimate publishers.