Garbage in, garbage out” applies just as much to AI-assisted vibe coding as it does to old-fashioned software development, as I learned the hard way.
Threat actors are publishing clean extensions that later update to depend on hidden payload packages, bypassing marketplace ...