Somewhere inside GitHub, a developer installed a Visual Studio Code extension. It looked like any other productivity plugin ...
GitHub confirmed an attacker was able to access its internal repositories after a code extension breach, with TeamPCP ...
The Megalodon supply chain attack poisoned over 5,500 GitHub repositories via automated commits injecting GitHub Actions workflows.