GitHub security breach: poisoned VS Code extension hits ~3,800 internal repos

GitHub security breach: poisoned VS Code extension hits ~3,800 internal repos
[[{„value”:”
GitHub is investigating a GitHub security breach after unauthorized access reached its internal repositories, and the fallout is already rippling far beyond the company itself. For developers, especially in crypto, the story quickly turned from a corporate incident into a personal warning: check your code, rotate your secrets, and assume anything hardcoded may now need attention.
The compromise was traced to a poisoned VS Code extension installed on an employee device, a detail that makes this more than another repo intrusion. It points to the kind of attack developers worry about most: a strike through trusted tools, where the route in looks routine until it suddenly is not.
GitHub says it detected and contained the breach on Tuesday. It removed the malicious extension, isolated the affected endpoint, rotated critical credentials, and launched incident response measures while continuing to analyze logs and monitor for further activity.
GitHub investigates a breach of inte

Czytaj więcej

We współpracy z: https://en.cryptonomist.ch/2026/05/20/github-security-breach-vs-code-extension/

Total
0
Shares
Dodaj komentarz

Podobne Wpisy