GitHub confirms breach of 3,800 repos via malicious VSCode extension | Hacker News
TL;DR AI
1 min readKey summary
GitHub said a malicious VS Code extension led to unauthorized access affecting about 3,800 repositories.
The case highlights how extension-based developer tools can create weak isolation and broad supply-chain risk.
It also underscores the need for stricter extension vetting, least-privilege access, and better repo segmentation.
