GitHub 官方发布更多细节:
一起员工设备被攻破,该事件涉及一个被污染的 VS Code 扩展。
这种方式我们
@SlowMist_Team 很早就公布过手法。真是醉了😵💫
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
显示更多