GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension
TL;DR
GitHub confirmed that the cybercrime group TeamPCP exfiltrated roughly 3,800 internal code repositories after compromising an employee device through a poisoned VS Code extension. The Microsoft-owned platform says no customer data was affected, but the breach highlights the growing threat of supply chain attacks targeting developer tools.
It is an unsettling irony when the world’s largest code-hosting platform becomes the victim of its own ecosystem. GitHub confirmed on Tuesday that a threat actor exfiltrated approximately 3,800 internal repositories after compromising an employee’s device through a poisoned Visual Studio Code extension, marking one of the most significant breaches the Microsoft-owned company has ever disclosed.
Github X post
The cybercrime group TeamPCP, also tracked as UNC6780, claimed credit for the attack on the Breached hacking forum, where it offered the stolen data, which it described as proprietary source code and internal organisation files, for at least $50,000. The group said...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE