Hackers Reached GitHub's Internal Repositories Through a VS Code Extension
Attackers compromised a Visual Studio Code extension to gain unauthorized access to GitHub's internal source code repositories. The breach, which exploited developer tooling supply chains, exposed internal projects and credentials stored in private repositories. GitHub has since revoked the compromised access tokens and is investigating the full scope of the intrusion.