GitHub confirms breach — thousands of internal repositories hit after employee installs malicious VS Code extension



  • GitHub confirms an employee’s compromised device led to exfiltration of internal repositories via a poisoned VSCode extension
  • Threat actors TeamPCP are selling an archive of roughly 4,000 repos on the dark web, asking $50,000 with samples shared for proof
  • The group is also behind recent npm supply‑chain attacks, highlighting its ongoing campaign against developer ecosystems

GitHub, one of the biggest open source code repositories in the world, has confirmed being hit by a cyberattack which saw its sensitive data stolen.

In a short announcement on X, GitHub saidone of its employees had their device compromised when they downloaded a poisoned VSCode extension.

https://cdn.mos.cms.futurecdn.net/2viAsX89eJReYQEQ3i3SwH-750-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img