logo

The Extension Blind Spot: How One VS Code Plugin Gave Attackers GitHub’s Source Code

ID: 4b00e68a-d902-5ca3-9444-267c4a982abe

STIX ID: report--4b00e68a-d902-5ca3-9444-267c4a982abe

Feed Name: Security Boulevard

Threat Score
92/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Jacob Krell

...
...

On May 19, 2026 TeamPCP compromised a GitHub employee via a malicious VS Code extension, exfiltrating 3,800 internal repositories; the report frames this as one event in a rapid campaign targeting developer tooling and IDE extensions, documents prior related compromises, and recommends controls such as allowed-extension policies, extension inventories, credential isolation, and developer workstation monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.