Somewhere inside GitHub, a developer installed a Visual Studio Code extension. It looked like any other productivity plugin ...
Microsoft has had a VS Code extension for a long time, and it finally came back to bite them.
GitHub confirmed attackers stole 3,800 internal repositories via a poisoned VS Code extension. The same threat group, TeamPCP ...
GitHub has confirmed that roughly 3,800 internal repositories were hacked after an employee installed an infected VS Code ...
The code hosting giant GitHub said it was investigating a breach but said there was no evidence of customer data theft.
A GitHub employee has unwittingly allowed 3,800 internal repositories to be breached after a device compromise with a poisoned VS Code extension.
GitHub, the world's biggest code repository and DevOps platform, fell victim to a malicious Visual Studio Code (VS Code) ...
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
GitHub lost 3,800 internal repos after poisoned Nx Console update exposed developer credentials and supply-chain risk.
GitHub is investigating a breach of its internal repositories after the TeamPCP hacker group claimed to have accessed ...
Researchers say the campaign abused compromised access tokens and deploy keys to inject malicious GitHub Actions workflows ...
GitHub confirmed an attacker was able to access its internal repositories after a code extension breach, with TeamPCP ...