GitHub updates security incident investigation: An employee's device was compromised, involving a contaminated VS Code extension

By: www.chaincatcher.com|2026/05/20 20:45:06

GitHub has updated the details of the investigation into the unauthorized access incident of its internal repositories: GitHub detected and contained an incident yesterday involving an employee's device being compromised, which involved a maliciously implanted VS Code extension. GitHub removed the malicious extension, isolated the affected terminals, and immediately initiated an incident response. Current assessments show that only GitHub's internal repositories experienced data exfiltration, and the approximately 3,800 repositories claimed by the attackers are roughly consistent with the investigation results. GitHub has prioritized rotating critical credentials, is analyzing logs, verifying credential rotations, and monitoring subsequent activities, with a complete report to be released after the investigation is concluded.

Additionally, Slow Mist's Chief Information Security Officer 23pds commented on this incident, stating: "By analyzing leaks from cybercrime forums, hackers may have used Anthropic's Mythos security AI to precisely breach GitHub's defenses and steal information from about 4,000 core internal repositories: including the source code for Copilot, the algorithms for CodeQL, the Actions runtime, and the entire billing system. Further analysis of this code could lead to subsequent attacks, having a profound security impact on the integration of the open-source community."

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

Echo Protocol confirms it has been attacked and suspends all cross-chain transactions

Echo Protocol announced that it is investigating a security incident affecting the Echo cross-chain bridge on Monad. During the investigation, all cross-chain transactions remain suspended.According to previous reports, market news indicated that Echo Protocol was hacked on Monad. The attacker minte...

Slow Fog CISO: Grok was alerted to an injection attack resulting in a $175,000 DRB anomaly transfer

The Chief Information Security Officer (CISO) of Slow Mist @23pds posted on the X platform revealing that X platform user Ilhamrfliansyh induced the AI model Grok to generate and publish abnormal content through a prompt injection attack, triggering erroneous on-chain fund operations.It is alleged t...

Slow Fog CISO: The Coinbase Commerce asset recovery page sitemap also has flaws, posing a phishing attack risk

After Slow Mist founder Yu Xian disclosed that the Coinbase Commerce asset recovery page directly requires users to enter plaintext mnemonic phrases, Slow Mist's Chief Information Security Officer 23pds added that the sitemap of that page also has flaws, allowing malicious attackers to easily use to...

Slow Fog releases MistTrack Skills: introducing on-chain AML risk analysis capabilities for AI Agents

Slow Mist announces the launch of MistTrack Skills, aimed at providing on-chain address risk analysis and anti-money laundering (AML) detection capabilities for AI Agents. In the context of the rapid development of AI Agents and the Skills ecosystem, this tool helps Agents automatically complete add...

Term Finance closes Meta Vaults after estimated $8.5M attack

CryptoQuant's Risk for Bitcoin: Ki Young Ju Identifies the Main Threat to Bitcoin

CryptoQuant's risk for Bitcoin is not linked to a sudden price crash, but rather to a much less dramatic scenario — a prolonged sideways movement. The founder of CryptoQuant, Ki Young Ju, believes that it is the boredom in the market that can slowly erode investors' faith in the future growth of the...
...
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com