And it's only getting worse with the waves of vibe-coders.
I actually wrote about this recently after poking around a popular extension that Antigravity users were installing. It's wild what people are doing with your credentials, and you'd have no idea! https://opista.com/posts/blind-trust-in-vs-code-extensions
I got in an argument with someone the other day that said their vibe coded app was more secure than something hand written because the ai “knows all exploits”.
We’re cooked.