Post

GitHub
GitHub@github·
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
510
3.2K
10.3K
5.4M
GitHub
GitHub@github·
2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.
English
17
148
1.3K
460.9K
Darren
Darren@CorboDT·
@github Just to be clear: Microsoft’s GitHub was compromised when a Microsoft developer using Microsoft VSCode installed a rogue extension from Microsoft’s VSCode extension library, which is moderated and hosted by Microsoft. I guess I’ll be reevaluating my life choices.
English
29
239
2.6K
386.7K
Chandru TG✨
Chandru TG✨@chandru_tg·
Quick question from a small business owner perspective: I have a live business website built entirely in VS Code and deployed directly from a GitHub repository (using GitHub Pages + custom domain). How does this latest change affect existing live sites like mine? Will there be any impact on deployment workflow, build process, or live performance? Would love a clear explanation — many small businesses and indie developers rely heavily on this exact VS Code + GitHub workflow.
English
5
0
9
41.4K
goc
goc@getorcreate·
@github What was the VS Code Extension? Help people out.
English
4
0
11
38.2K
Marwan
Marwan@marwanbuilds·
@github We need the name of the extension, please !
English
0
0
0
379
Ernesto Heine
Ernesto Heine@SeniorLazarus·
@github You could at least send a message that not affected accounts are safe. But Github is going to loose a huge deal without taking care of the psychological consequences of this. What a shame.
English
2
0
4
4.2K
Jesse
Jesse@jessefarinacci·
@github why does one developer have access to 3,800 repositories?
English
1
0
0
7.3K
Tim Dentry
Tim Dentry@Ja4h3ad·
@github I wonder how much of the installation of poisoned extensions is being driven by Cursor, Codex and Claude Code. To my knowledge, none of the vendors are performing SCA for the supply chain that their models "recommend" when generating code.
English
2
0
2
15.1K
Tanaka🔥
Tanaka🔥@taqs_blaze·
@github Could this possibly have compromised Microsoft accounts? I received a single-use code that i did not request
English
2
0
4
8.4K
Hetman Cyfrowy
Hetman Cyfrowy@MetaSarmata·
@github Liberum veto: Rzeczpospolita. Liberum install: GitHub. Pattern recognition.
GIF
Polski
0
0
1
4K
Sierra Trading
Sierra Trading@_sierratrading·
@github What is the definition of GitHub-internal repository?
English
1
0
0
7.7K
Kfir Gollan
Kfir Gollan@kfirgollan·
@github @grok are there vendors other than koi (now part of PaloAlto) that can prevent this?
English
3
0
0
23.2K
🩻
🩻@VendiendoChetos·
@github oh brudda. someone up top just wanted a quick payday. just confirmed the attack’s authenticity. easier to procure a buyer. rinse. and repeat
English
1
0
0
4.5K
Beatrix Vox
Beatrix Vox@beatrixvox·
@github Dumb question i know but I appreciate if you answer 😭
Beatrix Vox tweet media
English
8
1
38
12.3K
Beiron
Beiron@thebeiron·
@github GitHub you got to stop with L's. Soon enough the standard will become self hosted Git repos if this continues. Might be for the better though.
English
1
0
5
6.8K
Matt
Matt@stacks0x_·
@github Here's a thought, TELL US THE EXTENSION.
English
1
2
90
14.7K
Dr. Josh C. Simmons
Dr. Josh C. Simmons@drjoshcsimmons·
@github It’s one dumpster fire after another with you guys lately. Crazy how this comes so fast on the heels of the massive layoffs. Probably just coincidence…
English
5
1
188
29.1K
Warrior of America's Ragnarök
Warrior of America's Ragnarök@TNHillbillyHack·
@github How the fuck is your CI/CD pipeline for devs using tools not locked down. Are you fucking high? At the very least sack the fucks that loaded extension outside of what I assume are controls, which leads me back to question 1?
GIF
English
3
1
19
7.5K
Nitin Bisht
Nitin Bisht@nitinbisht96·
@github GitHub got hit through a VS Code extension. That's the threat model in 2026.
English
1
1
0
13K
Milton Cogo
Milton Cogo@milton_tapbit·
@github Poisoned VS Code extension as the entry vector that's a clever attack,trusted dev tools are exactly where security teams tend to look last. Good on GitHub for disclosing quickly, full transparency on root cause is what the community needs right now
English
4
1
18
9.2K
Penguinpecker
Penguinpecker@penguinpecker1·
@github Is there anything in tech that's not been hacked?
English
3
0
8
10.2K
Tay 💖
Tay 💖@tayvano_·
@github lmaoooooooo people have been literally BEGGING to help microsoft get their arms around the EASILY DETECTABLE shit in vscode for YEARS now rip motherfuckers
Krakovia@krakovia_evm

@ashtom @perplexity_ai can you fix the issue with people deploying malware in vscode extension marketplace? I'm getting tired of sending mails every week to vsmarketplace@microsoft.com, fix your fucking marketplace

English
7
35
791
101.9K
Sayooj
Sayooj@sayoojkeloth·
@github so the most secure repos in the world got taken down by a vs code extension
English
1
0
0
10.2K
Anotida Msiiwa
Anotida Msiiwa@anomsiiwa·
@github A Microsoft text editor extension taking down internal Microsoft code repositories is a brutal supply chain loop.
English
3
13
230
24.8K
Grok
Grok@grok·
Chat with the most truthful AI on Earth. Try Grok free today.
English
0
61
1.7K
14M
Paylaş