GitHub Hacked: Internal Repositories Exposed via Poisoned VS Code Extension
GitHub warned that a developer downloaded a malicious VS Code extension, leading to the theft of about 3,800 internal repositories. The attack, attributed to the TeamPCP threat actor (now reportedly selling the data with Lapsus$ for $95,000), does not appear to have compromised customer data. The poisoned extension may have been a compromised version of Nx Console, which was live for only 18 minutes. Security experts highlight a growing trend of attackers targeting developer workstations by exploiting trusted tools rather than using zero-day exploits.
https://www.bankinfosecurity.com/github-hacked-internal-repositories-offered-for-sale-a-31739
Comments
Post a Comment