r/netsec 🔐 Cybersecurity 👁 0

GitHub ~3,800 internal repos compromised through a malicious VS Code extension

The entry point wasn’t a CVE. It was a VS Code extension. One GitHub employee installed a malicious extension. That single install gave attackers access to secrets on the device. Those secrets were used to move laterally

📄

This source provides headlines only. Use the button below to read the complete article on the original site.

📰 Read the original article on r/netsec

Originally published by r/netsec. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.