TeamPCP gained access to GitHub's private source code after an employee unknowingly installed a malicious coding tool.
TeamPCP exfiltrated 3,800 internal GitHub repositories after poisoning a VS Code extension. No customer data was affected, the company says.
The code hosting giant GitHub said it was investigating a breach but said there was no evidence of customer data theft.
Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and ...
GitHub is investigating a cyberattack linked to a malicious VS Code extension after hackers allegedly accessed thousands of ...
Everyone should be using this feature.