GitHub breach via malicious VS Code extension exposes roughly 3,800 internal repos

“One poisoned VS Code extension reached roughly 3,800 internal GitHub repos. The tool you trust to write code is now the blast radius.”

7.5Weirdness

Why It Matters

The trusted builder interface becomes the attack surface, especially as developers install more AI/coding extensions and grant them broad local access.

Evidence

Source evidence is in the linked daily scan.

Caveat

Internal repos, no evidence of customer data outside affected repos per reporting; don't overstate.

Signal Read

Novelty: 8Receipts: 9Story voltage: 7Heat: 8

Source Trail

Daily scan: 2026-05-21

  • No public source URL captured yet.