Sometime in early 2025, an attacker slipped malicious code into a Visual Studio Code extension, and a GitHub employee ...
Sometime in early 2026, a software developer did what millions of programmers do every week: updated a dependency. The ...
GitHub confirms breach of 3,800 internal repos after employee installs poisoned VS Code extension - SiliconANGLE ...
The code hosting giant GitHub said it was investigating a breach but said there was no evidence of customer data theft.
GitHub CISO Alexis Wales confirmed Thursday that a poisoned build of the Nx Console Visual Studio Code extension — live on ...
GitHub confirmed a breach affecting about 3,800 internal repositories after an employee installed a malicious VS Code ...
A GitHub employee has unwittingly allowed 3,800 internal repositories to be breached after a device compromise with a ...
GitHub confirms an employee’s compromised device led to exfiltration of internal repositories via a poisoned VSCode extension ...
GitHub says the breach of roughly 3,800 internal repositories was tied to the wider TanStack npm supply-chain attack.
Microsoft is reportedly ending most internal use of Claude Code and directing engineers to move their workflows to GitHub ...