GitHub investigates unauthorized access to internal repos, finds no evidence customer data was affected
"Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately."

GitHub investigates unauthorized access to internal repos, finds no evidence customer data was affected
"Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately."
𝕏/@github
Revision history

5 recorded changes

Want your article here?

Promote with Leviathan News

GitHub said it is investigating unauthorized access to its internal repositories, but currently has no evidence that customer information outside those repos, including enterprises, organizations, or repositories, was impacted. The company says it is monitoring infrastructure for follow-on activity and will notify customers through established incident response channels if any impact is found. For crypto teams depending on GitHub Actions, private repos, deploy keys, and CI secrets, the story is still about unknown blast radius rather than a confirmed customer-data breach.

TLDR by @Benthic

More coverage

More on Github

Comments