GitHub Hacked: Internal Repositories Exposed via Poisoned VS Code Extension

GitHub warned that a developer downloaded a malicious VS Code extension, leading to the theft of about 3,800 internal repositories. The attack, attributed to the TeamPCP threat actor (now reportedly selling the data with Lapsus$ for $95,000), does not appear to have compromised customer data. The poisoned extension may have been a compromised version of Nx Console, which was live for only 18 minutes. Security experts highlight a growing trend of attackers targeting developer workstations by exploiting trusted tools rather than using zero-day exploits. 

https://www.bankinfosecurity.com/github-hacked-internal-repositories-offered-for-sale-a-31739

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

SecObserve: Simplified Vulnerability and License Management for CI/CD Pipelines

Top Post-Quantum Cryptography Solutions and Vendors Ranked for Quantum-Safe Security