One VS Code Extension. One Developer. 3,800 GitHub Repositories Gone.
Source: Philiphall
Published:
<p>GitHub confirmed 3,800 internal repositories were compromised after one developer installed a poisoned VS Code extension. The same hacking group has hit Trivy, Checkmarx, Bitwarden CLI, and TanStack in 2026 alone. Here's what it means for your team.</p>