My initial guess was that #VSCode was outdated or some of its plugins, and someone got access through that. But apparently, she didn't have it open. So how did the attackers managed to run it in the first place?
Malicious links?
Some kind of tunneling from other Apple devices?