2026-05-21 / Signal #5
GitHub breach via malicious VS Code extension exposes roughly 3,800 internal repos
“One poisoned VS Code extension reached roughly 3,800 internal GitHub repos. The tool you trust to write code is now the blast radius.”
7.5Weirdness
Why It Matters
The trusted builder interface becomes the attack surface, especially as developers install more AI/coding extensions and grant them broad local access.
Evidence
Source evidence is in the linked daily scan.
Caveat
Internal repos, no evidence of customer data outside affected repos per reporting; don't overstate.
Signal Read
Novelty: 8Receipts: 9Story voltage: 7Heat: 8
Source Trail
Daily scan: 2026-05-21
- No public source URL captured yet.