VS code/Cursor extensions are a supply chain attack waiting to happen, and have many times... They all contain a crazy amount of node/JS junk, they're often owned by randos, they silently update, nobody looks at them and the security model is shit. Use restricted marketplaces.
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.