GitHub.
The premier repository of code.
Compromised through a poisoned VS Code extn.
Β¬3,800 repositories exposed.
Itβs time to secure access with sandboxed, hardened biometrics through
@ThinC_AUTH, and protect API keys through hardened access & just-in-time authorization.
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.