GitHub ~3,800 internal repos compromised through a malicious VS Code extension
Source: Reddit r/netsec · Category: Supply Chain
Poisoned VS Code extension led to exfiltration of ~3,800 internal GitHub repositories at GitHub itself; customer data reportedly spared but scope unclear. Law firms using GitHub for code or IP storage face similar supply chain exposure; verify extension policies and monitor GitHub incident updates.