Switch language한국어
Back to the list

GitHub confirms breach of 3,800 repos via malicious VSCode extension | Hacker News

TL;DR AI

Key summary

1 min read
  1. GitHub said a malicious VS Code extension led to unauthorized access affecting about 3,800 repositories.

  2. The case highlights how extension-based developer tools can create weak isolation and broad supply-chain risk.

  3. It also underscores the need for stricter extension vetting, least-privilege access, and better repo segmentation.

Read the original