Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GHOST STADIUM Phishing Targets FIFA Fans With Fake
May 27, 2026
Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace
May 27, 2026
Grandoreiro Malware Targets Portuguese Banks & LatAm Firms
May 27, 2026
Home/CyberSecurity News/Weaponized VS Code Extension Breaches GitHub Internal Rep
CyberSecurity News

Weaponized VS Code Extension Breaches GitHub Internal Rep

GitHub confirmed a significant security breach on May 18, 2026. Attackers had exploited a weaponized Visual Studio Code extension to compromise an employee’s device, subsequently exfiltrating data...

Jennifer sherman
Jennifer sherman
May 21, 2026 2 Min Read
21 0

GitHub confirmed a significant security breach on May 18, 2026. Attackers had exploited a weaponized Visual Studio Code extension to compromise an employee’s device, subsequently exfiltrating data from the company’s internal source code repositories.

The attack was detected and contained on Monday, May 18, when GitHub’s security team identified suspicious activity on an employee endpoint.

The intrusion vector was traced to a poisoned VS Code extension, specifically a malicious version of the Nx Console extension published by a third party, which had been installed on the compromised device.

GitHub swiftly removed the malicious extension version from the marketplace, isolated the affected endpoint, and initiated full incident response procedures.

The threat actor behind the attack has claimed responsibility for exfiltrating approximately 3,800 internal repositories.

GitHub confirmed that this figure is “directionally consistent” with its ongoing investigation, making it one of the more significant supply chain-style attacks targeting a major DevOps platform in recent memory.

2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.

— GitHub (@github) May 20, 2026

GitHub’s current assessment indicates that the breach was limited to GitHub-internal repositories only.

Critically, the company stated it has found no evidence of impact to customer-facing infrastructure, including customer enterprises, organizations, or personal repositories hosted on the platform.

However, GitHub acknowledged that some internal repositories do contain customer-derived information such as excerpts from support ticket interactions raising the possibility of limited secondary exposure.

The company has pledged to notify affected customers directly through established incident response and disclosure channels if any impact to customer data is confirmed.

In a rapid containment effort, GitHub’s security team began rotating critical secrets as early as Monday and continued through Tuesday, prioritizing credentials with the highest potential blast radius. The company continues to:

  • Analyze logs for signs of lateral movement or follow-on activity
  • Validate that all rotated secrets have been fully invalidated
  • Monitor platform infrastructure for any persistence mechanisms or secondary access attempts

The attack highlights the growing danger of VS Code extension supply chain attacks. The Nx Console extension, widely used in Angular and monorepo development workflows, was subverted at the distribution level, meaning developers with the compromised version installed were unknowingly exposed.

GitHub stated it will publish a comprehensive post-incident report once the investigation concludes. The company’s transparency around the breach, including directional acknowledgment of the attacker’s repository count claims, reflects a measured but proactive disclosure posture.

Organizations relying on GitHub for internal development workflows are advised to audit installed VS Code extensions, review extension update policies, and monitor for any unusual API or repository access activity as the investigation continues.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft Defender 0-Day Flaws Actively Exploited Wild

Next Post

P2PInfect Botnet Compromises Kubernetes via Clusters Through

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Top CISOs Boost Risk Visibility to Prevent Critical Incidents
May 27, 2026
Hackers Push Malicious Software Via AI Chatbot Recommendations
May 27, 2026
Motorola Preinstalled App Hijacks Amazon for Affiliate Codes
May 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us