GitHub updates security incident investigation: An employee's device was compromised, involving a contaminated VS Code extension
GitHub has updated the details of the investigation into the unauthorized access incident of its internal repositories: GitHub detected and contained an incident yesterday involving an employee's device being compromised, which involved a maliciously implanted VS Code extension. GitHub removed the malicious extension, isolated the affected terminals, and immediately initiated an incident response. Current assessments show that only GitHub's internal repositories experienced data exfiltration, and the approximately 3,800 repositories claimed by the attackers are roughly consistent with the investigation results. GitHub has prioritized rotating critical credentials, is analyzing logs, verifying credential rotations, and monitoring subsequent activities, with a complete report to be released after the investigation is concluded.
Additionally, Slow Mist's Chief Information Security Officer 23pds commented on this incident, stating: "By analyzing leaks from cybercrime forums, hackers may have used Anthropic's Mythos security AI to precisely breach GitHub's defenses and steal information from about 4,000 core internal repositories: including the source code for Copilot, the algorithms for CodeQL, the Actions runtime, and the entire billing system. Further analysis of this code could lead to subsequent attacks, having a profound security impact on the integration of the open-source community."
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Echo Protocol confirms it has been attacked and suspends all cross-chain transactions

Slow Fog CISO: Grok was alerted to an injection attack resulting in a $175,000 DRB anomaly transfer

Slow Fog CISO: The Coinbase Commerce asset recovery page sitemap also has flaws, posing a phishing attack risk

Slow Fog releases MistTrack Skills: introducing on-chain AML risk analysis capabilities for AI Agents

Why 89% of tokenized RWAs remain idle despite a $34.6 billion market: Falcon exec explains

$52.5 Billion Net Exposure Differed from Official Net Assets

Cardano Spends 23.6 Million Francs, On-Chain Audit Confirmed

DefiLlama and Forgd introduce institutional token grades, but warn that AAA does not mean risk-free

21-bank stablecoin has global backing, but can it rival USDT and USDC?

Bitcoin faces a two-week Fed trap as inflation rewrite threatens to upend rate cuts

The source on Naura and 3D DRAM memory is unavailable

Ubuntu 26.10 Releases Snapshot 3 for Testing Ahead of October Launch

Kalshi faces $500,000 daily fines as Michigan forces sports event contracts offline

30-Year Bond Yield Hits 4.079%, Raising Funding Costs for MetaPlanet's Bitcoin Purchases

Quantum Memory: The Device That Breaks Bitcoin and Replaces It

Japan’s 4% bond yield spike threatens the low-cost borrowing strategy behind corporate Bitcoin buying

Anthropic's Mea Culpa: A Complete Autopsy of Claude's Missteps

Arthur Hayes calls EUR/JPY prices crypto’s smoke alarm, but the Fed’s plumbing still shows no fire

Debate Over $300 Bitcoin Tax Exemption and Estimated Revenue Increase

Copy Trading: How Does It Work in 2026?

PL Deputy Proposes Gun Carrying Rights for Cryptocurrency Investors and Industry Executives

The Executive Who Anticipates a New Era for Cryptocurrencies: "We Are Just Getting Started"

Why GENIUS could leave digital dollars vulnerable to sudden blockchain network ‘bank runs’

Robinhood Chain Down for 14 Minutes: The Blockchain That Was Supposed to Tokenize Wall Street First Blocked Itself

Netflix Hits British Wallets with Up to 33.4% Price Increase on Plans

Cracking 1.33 Trillion Daily Tokens: B.AI Powers the “AI Grid” with Full-Stack Infrastructure to Fuel the Agentic Era

Hyperliquid vs Drift Protocol Whitepaper Comparison (2026): Technology, Tokenomics, and Trading Infrastructure

Cybercrime, Child Gambling, and Underground Banking

PostGREShell: flaw in PostgreSQL turned backup accounts into backdoors








