todayonchain.com

GitHub Internal Repositories Breached via VS Code Extension

Cointelegraph
GitHub is investigating unauthorized access to internal repositories following a security breach involving a compromised employee device and a malicious VS Code extension.

Summary

GitHub confirmed it is investigating a security incident where unauthorized actors gained access to internal repositories through a compromised employee device. The breach was linked to a malicious version of a VS Code extension, which the company has since isolated. While GitHub maintains there is no current evidence of impact to customer information, the hacking group TeamPCP has claimed responsibility, alleging they possess 4,000 private code repositories. Binance founder Changpeng Zhao has urged developers to rotate API keys as a precaution following this event.

(Source:Cointelegraph)