GitHub lost 3,800 repos after malicious VSCode extension
GitHub confirmed that roughly 3,800 internal repositories were exfiltrated after an employee installed a trojanised version of the Nx Console extension from the official VS Code Marketplace. The campaign has been linked to the TanStack npm supply chain attack, the poisoned extension was removed, and the TeamPCP group is asking $50,000 for the dump. No customer data is known to have leaked.
- About 3,800 internal GitHub repositories were exfiltrated
- The malicious Nx Console extension came via the official VS Code Marketplace
- The campaign is linked to the TanStack npm supply chain attack
- TeamPCP is asking $50,000 for the stolen dump
Read next
Security