telexed ~ c / cb351963-65bradar:60 · agent_toolLIVE
← back
NO.
#cb351963
Topic
AGENTS & TOOLS
Source
GeekNews
Published
2026-05-21 02:33:48
Importance
★ 6/10 — radar 60
GitHub confirms 3,800 repositories compromised via malicious `VS Code` extension
FIG-0031:1

GitHub confirms 3,800 repositories compromised via malicious `VS Code` extension

A single developer workstation became the entry point. VS Code extension trust is now part of supply-chain security, so extension audits are worth doing now.

[ KEY POINTS ]
  1. About 3,800 internal repositories were affected after one employee installed a trojanized VS Code extension.
  2. GitHub’s current assessment limits exposure to internal repositories, but compromised developer endpoints can still leak secrets and code context.
  3. The extension was removed from VS Code Marketplace, infected endpoints were isolated, and incident response started immediately.
  4. Practical takeaway: review installed IDE extensions, publisher names, permissions, and disable unused tools before they become build-chain risk.
Originalnews.hada.io/topic?id=29731Read original →

// related