A malicious VS code extension just breached GitHub ‘s internal repositories

Source: Security Affairs  ·  Category: Supply Chain


Trojanized VS Code extension led to breach of ~3,800 GitHub internal repositories; TeamPCP claims credit and demands $50K ransom. Developer tooling supply chain risk; law firms using GitHub for internal or matter-related code face similar extension-based compromise vectors.

→ Read the full article

Read more