GitHub hit by a compromised VSCode extension
Source: Reddit r/netsec · Category: Supply Chain
Malicious VS Code extension compromised GitHub repositories. If firm uses VS Code for development or code review workflows, supply chain risk is material; audit internal developer toolchains and extension manifests immediately.