GitHub confirmed a major security breach in which attackers exfiltrated code from approximately 3,800 internal repositories after compromising an employee device via a poisoned VS Code extension. The attack is attributed to the TeamPCP threat group, which is threatening to sell or leak the stolen code. The same campaign on May 19 also backdoored the popular Nx Console VS Code extension — exposing thousands of developers for 18 minutes — and published 637 malicious npm package versions under the AntV namespace. TeamPCP's pattern involves exploiting platform update mechanisms or stolen credentials to execute rapid supply chain attacks against widely trusted open-source tools before defenders can respond, with prior targets including the Trivy scanner and Axios npm library.

4m read timeFrom csoonline.com
Post cover image
1 Impression