Malicious VS Code Extension Exposes 3,800 GitHub Private Repos, Hacker Sells Code for $50K
On May 20, GitHub disclosed that a compromised VS Code extension installed by an employee allowed the hacker group TeamPCP to steal credentials, clone roughly 3,800 private repositories, and list the source code for a $50,000 auction on the dark web, highlighting a severe software‑supply‑chain threat.
