Post

GitHub
GitHub@github·
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
583
3.6K
11.5K
7.4M
GitHub
GitHub@github·
2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.
English
17
160
1.5K
565K
GitHub
GitHub@github·
3/ We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first.
English
8
96
1.2K
406.2K
GitHub
GitHub@github·
4/ We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.
English
6
91
1.1K
432.3K
GitHub
GitHub@github·
5/ We will publish a fuller report once the investigation is complete.
English
24
91
1.3K
403.2K
R
R@SQUIRTDRINKER17·
@github Everything Microsoft buys goes to shit. Get your shit together why are employees with access to so much crap even allowed to access 3rd party marketplaces let alone have internet access?
English
1
0
4
6.4K
Babak Morshedizadeh
Babak Morshedizadeh@iambmorsh·
@github Did any specific private repo get exposed, if so, will you notify the account owners ASAP??
English
1
0
2
6.6K
Circumjovial
Circumjovial@CircumjovialLLC·
@github Anybody know yet if the malicious VS Code extension was poisoned by a malicious npm package? If so, this is a trifecta for Microsoft. A trifuckta, if you will.
English
0
1
15
7.6K
レオン男爵
レオン男爵@BaronLeon86·
6/ Worst case, the leaked repos had customer data and unrotated secrets inside. They’re already being exploited, millions of accounts are screwed. GitHub’s trust is completely fucked and a long crisis is unavoidable. Praying this never happens… or we’re all updating resumes while getting roasted in 4K 😂
English
0
0
5
6.7K
Nick Young
Nick Young@nyou045·
@github What's the likelihood this results in a global GitHub outage?
English
0
0
0
3K
Louis Vuitton
Louis Vuitton@LouisVuitton·
Relive the Cruise 2027 Show by Nicolas Ghesquière.
Français
719
1.2K
13.1K
47.1M
KHAWRIZM
KHAWRIZM@khawrzm·
@github You erased my `khawrizmi` & `gratechx` accounts without warning, acting as absolute gatekeepers. Today, your own internal repos are breached by a poisoned VS Code extension. Centralized clouds are a fragile liability. Sovereign Engineering is the cure. The algorithm returns home
English
1
1
1
37
White Rabbitx 🏴‍☠️
@github Secret rotation is critical, but the bigger question is extension trust, endpoint hardening, and how much implicit trust dev tooling still gets in 2026. We need to fix those supply chain attacks it gets the upper hand
English
0
0
0
1.5K
tenet
tenet@2026_tenet_1952·
@github They have seen and they know exactly what you didn’t want them to.
English
0
0
0
2.7K
Pratik Patel
Pratik Patel@PratikPatel_227·
@github They claimed to have 4000+ Repos and selling stuff for $50k+ Price
English
0
0
1
1.9K
Matthew
Matthew@Maverick_142·
@github We need to send them Hotpocket's and Surge Immediately!
English
0
0
0
2.5K
Paylaş