Top Stories
5 outlets·7 reports

GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension

ThinkingNews Desk · how this was written

GitHub is investigating unauthorized access to its internal code repositories after a breach that compromised thousands of them. The intrusion was traced to a malicious Visual Studio Code extension installed by an employee, allowing hackers to steal data from the affected repositories. No evidence has been presented that customer-hosted data outside GitHub’s own repositories was impacted.

Written from all 5 reports below, not from any single one.

How it was reported

  1. Ars Technica·
    In stunning display of stupid, secret CISA credentials found in public GitHub repo
  2. Hacker News·
    GitHub is investigating unauthorized access to their internal repositories
  3. TechMeme·
    GitHub says it's investigating "unauthorized access" to its internal repositories, and there's no proof of customer data outside its repositories being impacted (@github)
  4. Hacker News·
    GitHub Compromised
  5. TechMeme·
    GitHub confirms breach of ~3,800 repositories after one of its employees installed a malicious VS Code extension; TeamPCP claimed responsibility for the hack (Sergiu Gatlan/BleepingComputer)
  6. TechCrunch·
    GitHub says hackers stole data from thousands of internal repositories
  7. The Next Web·
    GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension

Related stories

Share: