Briefing Findings · A malicious VS Code extension is reported
Story-specific findings extracted from this briefing's coverage. Fast Facts in the sidebar holds the canonical reference data (CEO, founded, ticker).
What to Watch
-
Audit developer machines for recently installed VS Code extensions and remove anything untrusted.
BleepingComputer
-
Check CI/workflow repositories for signs of CI-driven backdooring (especially workflow changes).
safedep.io
What Changed
-
GitHub confirms breach of 3,800 repos via malicious VSCode extension
bleepingcomputer.com
-
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
BleepingComputer