GitHub just got hacked, a single VS Code extension did it.
→ Nx Console (2.2M installs) got hijacked, credential stealer hidden in an orphan commit
→ it harvested tokens from GitHub, npm, AWS, Kubernetes, even 1Password
→ a GitHub employee installed it
→ attackers accessed ~3,800 of GitHub's internal repositories
→ threat actor "TeamPCP" is now selling the stolen data on the dark web
→ the poisoned version was live for only 11 minutes before detection
→ GitHub confirmed it and spent the night rotating all critical secrets
one extension, 11 minutes. 3,800 internal repos compromised.
check your extensions right now.
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.