A Single Developer Downloaded a Poisoned VS Code Extension, and Now Look. GitHub warned late Tuesday that hackers stole roughly 3,800 internal repositories from the Microsoft-owned platform after a developer used a poisoned VS Code script, which is developed by Microsoft. TeamPCP and Lapsus$ appear to be cooperating to sell the stolen data for $95,000.
First seen on govinfosecurity.com
Jump to article: www.govinfosecurity.com/github-hacked-internal-repositories-offered-for-sale-a-31739
![]()

