1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
We are investigating unauthorized access to GitHubβs internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHubβs internal repositories (such as our customersβ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.