GitHub ~3,800 internal repos compromised through a malicious VS Code extension
The entry point wasn’t a CVE. It was a VS Code extension. One GitHub employee installed a malicious extension. That single install gave attackers access to secrets on the device. Those secrets were used to move laterally
📄
This source provides headlines only. Use the button below to read the complete article on the original site.
📰 Read the original article on r/netsec
Originally published by r/netsec. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.