Ссылка
click to show
click to show
Github hacked...
Summary
GitHub confirmed a security incident involving a poisoned VS Code extension that led to unauthorized access to around 3,800 internal repositories. So far, there is no indication that customer repositories or external user data were affected.
Quotes
Quote
„Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension”.
Quote
„The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far”.
My thoughts
This is a strong reminder that supply chain attacks can have serious consequences even when the initial vector looks small. What stands out here is that a single compromised developer tool was enough to open a path into internal company resources. Incidents like this will likely push organizations to tighten extension approval, endpoint monitoring, and developer workstation controls. Also... It sucks. Who needs computers anyway... right?
Sources