MEDIUMSupply Chain
Global

GitHub says internal repositories were taken in poisoned VS Code extension attack

·Source: CyberScoop

Updated:

Executive Summary

GitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension, an incident that underscores the growing risks facing software development platforms and the ecosystems built around third-party developer tools. The Microsoft-owned company said in posts on X that it detected and contained the […] The

Analysis

GitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension, an incident that underscores the growing risks facing software development platforms and the ecosystems built around third-party developer tools. The Microsoft-owned company said in posts on X that it detected and contained the […] The post GitHub says internal repositories were taken in poisoned VS Code extension attack appeared first on CyberScoop .
Source Attribution

Originally published by CyberScoop on May 20, 2026.

Related Threats