Hackers breach GitHub and access 3,800 internal repositories now listed for sale

TL;DR AI
2 min readKey summary
Hackers reportedly used a malicious VS Code extension to compromise a GitHub developer and steal credentials.
Using the stolen access, they reached GitHub infrastructure and accessed around 3,800 internal repositories.
The attackers are now trying to sell the stolen source code and related data on a cybercrime forum.
The incident highlights how trusted developer tools can be abused in software supply chain attacks at scale.
