It turns out that some participants post .blend files, which are used by the popular Blender open-source 3D modeling system.
Critical vulnerabilities in four widely used VS Code extensions could enable file theft and remote code execution across 125M installs.