A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
…Both media reports and Nx's own statements tie the malicious build to the compromise of a GitHub employee's developer machine, and that single compromise is how a credential stealer in…