Switch language한국어
Back to the list

GitHub confirms 3,800 internal repos stolen through poisoned VS Code extension as supply chain worm hits Microsoft's Python SDK

TL;DR AI

Key summary

2 min read
  1. GitHub confirmed a poisoned VS Code extension on an employee’s device exposed about 3,800 internal repositories.

  2. The breach is tied to TeamPCP, also tracked as UNC6780, a financially motivated group behind the Mini Shai-Hulud worm.

  3. The same actor is running a broader supply-chain campaign across npm and PyPI, including other package compromises.

  4. The incident highlights how one compromised developer tool can reveal internal code and infrastructure details at scale.

Read the original