Tech

An attacker got hold of unauthorized access to GitHub’s ~3,800 internal repositories

GitHub has since detected and contained a compromise of an employee device involving a poisoned VS Code extension.

GitHub has removed the malicious extension version, isolated the endpoint, and began incident response immediately, according to their claims.

Their current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with their investigation so far. They have moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first.

GitHub continues to analyze logs, validate secret rotation, and monitor for any follow-on activity. They have said that they will take additional action as the investigation warrants. They will publish a fuller report once the investigation is complete.

Source: GitHub

3
0
100%
Login to join the Conversation
Be the first one to participate!
Tech

Space for discussing the latest advancements in technology and everything related to it.