GitHub: Employee targeted by malicious VS Code plugin attack, approximately 3,800 internal repositories stolen

robot
Abstract generation in progress

BlockBeats News, May 20th, GitHub announced investigation details regarding an unauthorized access incident involving its internal repositories. The announcement states that yesterday, GitHub detected and contained an incident involving a malicious VS Code plugin on an employee device. GitHub has removed the malicious plugin version, isolated the endpoint, and immediately initiated incident response.

Currently, assessments show that the activity only involved the theft of GitHub internal repositories. The approximately 3,800 repositories claimed by the attacker are consistent with GitHub's ongoing investigation focus. GitHub has acted swiftly to reduce the risk, rotating key credentials yesterday and overnight, prioritizing the most impacted credentials. GitHub will continue analyzing logs, verifying key rotations, and monitoring subsequent activity, with a more comprehensive report to be released after the investigation is complete.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned