GitHub Got Hacked Through a VS Code Extension. Here's the Full Technical Story.
On May 18, a poisoned Nx Console VS Code extension was live on Microsoft’s marketplace for 18 minutes. One GitHub employee installed it. By May 20, ~3,800 internal repos were reportedly exfiltrated and auctioned for $50K. Here’s the full attack chain, payload analysis.