GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub confirmed that attackers breached 3,800 repositories by exploiting a malicious Visual Studio Code extension. The extension was crafted to steal authentication tokens from developers, enabling unauthorized access to their private code repositories. GitHub has revoked compromised tokens and is notifying affected users.