GitHub Confirms 3,800 Internal Repos Stolen Through Poisoned VS Code Extension
GitHub has confirmed that approximately 3,800 internal repositories were stolen due to a compromised Visual Studio Code (VS Code) extension. The breach occurred when attackers exploited a vulnerability in the extension, allowing them to access sensitive data. GitHub has since taken measures to secure its systems and is investigating the incident further. Users are advised to review their security practices and update their extensions to prevent similar attacks. The incident highlights ongoing security risks associated with third-party software integrations in development environments.
Read the full article: Decrypt