The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub’s Source Code
ID: 4b00e68a-d902-5ca3-9444-267c4a982abe
STIX ID: report--4b00e68a-d902-5ca3-9444-267c4a982abe
Feed Name: Security Boulevard
Threat Score
On May 19, 2026 TeamPCP compromised a GitHub employee via a malicious VS Code extension, exfiltrating 3,800 internal repositories; the report frames this as one event in a rapid campaign targeting developer tooling and IDE extensions, documents prior related compromises, and recommends controls such as allowed-extension policies, extension inventories, credential isolation, and developer workstation monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
