Unauthorized Access to GitHub Internal Repositories Traced to a Malicious VS Code Extension; About 3,800 Items May Have Been Leaked

TL;DR AI
2 min readKey summary
GitHub says a malicious Visual Studio Code extension compromised an employee device and led to unauthorized access to internal repositories.
The company says only internal repositories may have been affected and has removed the extension version from distribution.
GitHub is revoking and rotating critical credentials as a precaution while investigating the scope of the breach.
The attacker’s claim of about 3,800 leaked repositories appears to match GitHub’s current findings.



