logo

GitHub confirms breach of 3,800 repos via malicious VSCode extension

ID: ceac8bcc-7814-56a4-8de2-0502b7d9960d

STIX ID: report--ceac8bcc-7814-56a4-8de2-0502b7d9960d

Feed Name: DataBreaches.Net

Threat Score
85/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Dissent

...
...

GitHub detected and contained a compromise of an employee device caused by a poisoned VS Code extension that was trojanized; the malicious extension has been removed and the affected endpoint isolated. The company assessed that the activity involved exfiltration of GitHub-internal repositories, with the attacker’s claim of roughly 3,800 repositories being directionally consistent with the investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.