ended5월 21일· 1 sources

GitHub, 악성 VSCode 확장을 통한 3,800개 저장소 침해 확인

Why it matters

This breach reveals a critical vulnerability in VS Code's extension ecosystem: open marketplaces designed for convenience enable sophisticated supply chain attacks targeting even major platforms like GitHub. The incident, where 3,800 repositories were compromised through a single malicious extension, underscores how developer tools have become prime targets for attackers and emphasizes the urgent need for stricter vetting and governance controls over third-party software installation.

1
Sources
+0
24h
Growth
123d
Active
GitHubVS Code extensionSupply chain attackMalwareCredential theft

Sources

Related Issues