GitHub says internal repositories were impacted in poisoned VS Code extension attack

Source: CyberScoop  ·  Category: Supply Chain


GitHub internal repositories exfiltrated after employee device compromised via poisoned VS Code extension; 3,800 internal repos affected. VS Code is widely used by law firm developers; malicious extensions pose supply chain and insider-risk threat. Audit VS Code marketplace extension usage and disable auto-update for untrusted sources.

→ Read the full article

Read more