WeSearch

A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain

Adam Conway· ·15 min read · 0 reactions · 0 comments · 15 views
#cybersecurity#github#microsoft#software#technology
A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
⚡ TL;DR · AI summary

A compromised Visual Studio Code extension led to a significant breach at GitHub. The malicious extension, which had millions of installs, allowed attackers to steal credentials from a GitHub employee's machine. Microsoft, which operates the marketplace for these extensions, is facing scrutiny for the security lapse.

Key facts
Original article
XDA Developers · Adam Conway
Read full at XDA Developers →
Opening excerpt (first ~120 words) tap to expand

{ "@context": "https://schema.org", "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": "1", "name": "Home", "item": "https://www.xda-developers.com/" }, { "@type": "ListItem", "position":"2", "name": "Software and Services", "item": "https://www.xda-developers.com/software-and-services/" }, { "@type": "ListItem", "position":"3", "name": "A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain", "item": "https://www.xda-developers.com/poisoned-vs-code-extension-github-breach-microsoft-owns-every-link/" } ] } A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain By Adam Conway Published May 26, 2026, 6:00 PM EDT I’m Adam Conway, an Irish technology fanatic with a BSc in Computer…

Excerpt limited to ~120 words for fair-use compliance. The full article is at XDA Developers.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from XDA Developers