Evil-twin Open VSX extension install from known malicious namespace
This rule detects the installation of malicious VS Code extensions by monitoring file system writes within common VS Code and VS Code Server extension directories. It specifically alerts on a predefined list of extension namespaces associated with a known malicious coordinated campaign that impersonated legitimate publishers.
Microsoft Sentinel (KQL)

