Briefing Findings · A malicious VS Code extension and CI workflow techniques
Story-specific findings extracted from this briefing's coverage. Fast Facts in the sidebar holds the canonical reference data (CEO, founded, ticker).
What to Watch
-
Check for additional details on the VS Code extension compromise affecting internal GitHub repositories.
BleepingComputer
What Changed
-
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
safedep.io
-
mass github repo backdooring via CI workflows(Megalodon)
safedep.io
-
GitHub confirms breach of 3,800 repos via malicious VSCode extension
bleepingcomputer.com