GitHub confirms 3,800 repositories were accessed through a malicious VS Code extension tied to earlier internal repo investigation
EDITOR BRIEF
GitHub confirmed that a malicious VS Code extension led to unauthorized access affecting about 3,800 repositories. The report follows an earlier discussion about GitHub investigating access to internal repositories in May 2026.
INSIGHTS
The incident highlights how developer tooling has become a high-value attack path, especially when extensions have broad access to source code. Expect more scrutiny of extension supply chains, permissions, and enterprise controls around IDE integrations.
COMMENTS
Discussion
> geekhaus:~$ next read?

