GitHub Internal Repositories Breached via VS Code Extension
Summary
GitHub confirmed it is investigating a security incident where unauthorized actors gained access to internal repositories through a compromised employee device. The breach was linked to a malicious version of a VS Code extension, which the company has since isolated. While GitHub maintains there is no current evidence of impact to customer information, the hacking group TeamPCP has claimed responsibility, alleging they possess 4,000 private code repositories. Binance founder Changpeng Zhao has urged developers to rotate API keys as a precaution following this event.
(Source:Cointelegraph)