GitHub Hacked Through a Poisoned VS Code Extension — 3,800 Internal Repositories Compromised
A single GitHub employee installed a trojanized VS Code extension — and attackers walked away with roughly 3,800 internal repositories. Here's what happened, who's behind it, and how to vet your own extensions before the same thing happens to you.