GitHub confirmed that approximately 3,800 internal repositories were breached after an employee installed a malicious VS Code extension, which the company removed from the marketplace and contained. The breach has been linked to the TanStack npm supply-chain attack and the TeamPCP hacker group, which claimed responsibility and demanded at least $50,000 for the stolen data.
1 comment
GitHub confirmed that approximately 3,800 internal repositories were breached after an employee installed a malicious VS Code extension, which the company removed from the marketplace and contained. The breach has been linked to the TanStack npm supply-chain attack and the TeamPCP hacker group, which claimed responsibility and demanded at least $50,000 for the stolen data.