ended5월 21일· 1 sources
GitHub, 악성 VSCode 확장을 통한 3,800개 저장소 침해 확인
Why it matters
This breach reveals a critical vulnerability in VS Code's extension ecosystem: open marketplaces designed for convenience enable sophisticated supply chain attacks targeting even major platforms like GitHub. The incident, where 3,800 repositories were compromised through a single malicious extension, underscores how developer tools have become prime targets for attackers and emphasizes the urgent need for stricter vetting and governance controls over third-party software installation.
1
Sources
+0
24h
—
Growth
123d
Active
GitHubVS Code extensionSupply chain attackMalwareCredential theft