5 outlets·7 reports
GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension

ThinkingNews Desk · how this was written
GitHub is investigating unauthorized access to its internal code repositories after a breach that compromised thousands of them. The intrusion was traced to a malicious Visual Studio Code extension installed by an employee, allowing hackers to steal data from the affected repositories. No evidence has been presented that customer-hosted data outside GitHub’s own repositories was impacted.
Written from all 5 reports below, not from any single one.
How it was reported
- Ars Technica·In stunning display of stupid, secret CISA credentials found in public GitHub repo
- Hacker News·GitHub is investigating unauthorized access to their internal repositories
- TechMeme·GitHub says it's investigating "unauthorized access" to its internal repositories, and there's no proof of customer data outside its repositories being impacted (@github)
- Hacker News·GitHub Compromised
- TechMeme·GitHub confirms breach of ~3,800 repositories after one of its employees installed a malicious VS Code extension; TeamPCP claimed responsibility for the hack (Sergiu Gatlan/BleepingComputer)
- TechCrunch·GitHub says hackers stole data from thousands of internal repositories
- The Next Web·GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension
Related stories
- Dangerous New Linux Exploit Gives Attackers Root Access to Countless Computers3 outlets
- Framework customer information was accessed as part of a data breach3 outlets
- App host Vercel says it was hacked and customer data stolen4 outlets
- Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps3 outlets