Archive: https://archive.today/RQL78
From the post:
>GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
The company has since removed the unnamed trojanized extension from the VS Code marketplace and has secured the compromised device.
"Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately," the company said.
Archive: https://archive.today/RQL78
From the post:
>>GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
The company has since removed the unnamed trojanized extension from the VS Code marketplace and has secured the compromised device.
"Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately," the company said.