The Wild West of VS Code extensions and how a poisoned extension breached GitHub
Source: Aikido.Dev
Published:
<p>It's been a hard week for GitHub. Yesterday GitHub confirmed it had been breached . The attackers reportedly pulled data from roughly 4,000 internal repositories , and the entry point was a poisoned VS Code extension running on a GitHub employee's machine.</p> <p>The day before, Nx Console (a pop