Switch language한국어
Back to the list

GitHub internal information leaked; about 3,800 repositories were accessed without authorization via a Visual Studio Code extension

TL;DR AI

Key summary

2 min read
  1. GitHub said a malicious Visual Studio Code extension compromised an employee device and triggered a security incident.

  2. The company removed the poisoned extension, rotated sensitive secrets, and contained the breach.

  3. Attackers may have accessed data from about 3,800 internal repositories, but customer data impact has not been confirmed.

  4. The case highlights how trusted developer tools can be used as a supply-chain path for credential theft and source-code exposure.

Read the original