Posts tagged with "supply chain attack"

Found 1 post

How a single VS Code extension hacked GitHub

GitHub didn't get hacked by a master hacker breaking encryption. It got hacked because an employee installed a single poisoned VS Code extension. That one extension — with over 2 million installs — gave attackers access to tokens, AWS keys and password vaults, letting them pull ∼3,800 internal GitHub repositories. It's a reminder that private code isn't breached, it's handed over by mistake through the tools we trust every day.

By tuabuh