VS Code Extension Installation (Potential Token Theft via Jupyter Notebook)
Detects command-line installation of VS Code extensions. Malicious Jupyter notebooks can simulate keystrokes to silently install rogue extensions that steal GitHub tokens.
Microsoft Sentinel (KQL)

