头条
5 家媒体·7 篇报道

GitHub确认黑客在员工安装了受污染的VS Code扩展后窃取了数千个内部代码仓库

GitHub正在调查一起未授权访问其内部代码仓库的事件,数千个仓库因此被泄露。调查显示,入侵源于一名员工安装的恶意Visual Studio Code扩展,使黑客能够窃取受影响仓库中的数据。目前尚无证据表明GitHub自身仓库之外的客户托管数据受到影响。

本文综合以下全部报道写成,而非依据任何单一来源。

本页由机器翻译生成,原始报道为其原文语言。

各家媒体如何报道

  1. Ars Technica·
    In stunning display of stupid, secret CISA credentials found in public GitHub repo
  2. Hacker News·
    GitHub is investigating unauthorized access to their internal repositories
  3. TechMeme·
    GitHub says it's investigating "unauthorized access" to its internal repositories, and there's no proof of customer data outside its repositories being impacted (@github)
  4. Hacker News·
    GitHub Compromised
  5. TechMeme·
    GitHub confirms breach of ~3,800 repositories after one of its employees installed a malicious VS Code extension; TeamPCP claimed responsibility for the hack (Sergiu Gatlan/BleepingComputer)
  6. TechCrunch·
    GitHub says hackers stole data from thousands of internal repositories
  7. The Next Web·
    GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension