GitHub says internal repos exfiltrated after poisoned VS Code extension attack

2026-05-20T19:23:59Z46b83938c51bcb1caab4f83df1838f7c4b3eeb20801bc9a57fa6cabab649eba7
code-signingcredentials-exposeddata-exfiltrationdrupalgithublinux-kernelmacos-malwarenginx-riftnpmpatch-managementransomwaresoftware-supply-chainsupply-chain-attackvs-code-extension

What happened

A string of high-impact security incidents and supply-chain attacks dominated the roundup: GitHub says internal repositories were exfiltrated after a poisoned VS Code extension, multiple npm/TanStack cache-poisoning and Shai-Hulud supply-chain compromises spread credential-stealing malware, and researchers flagged active exploitation of NGINX Rift and Linux kernel privilege-escalation flaws. Microsoft disrupted an illegal code‑signing operation used by ransomware gangs while other stories detail exposed secrets in open GitHub repos, a critically urgent Drupal core patch, macOS stealer/backdoor

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
46b83938c51bcb1caab4f83df1838f7c4b3eeb20801bc9a57fa6cabab649eba7
Enrichment time
2026-05-20T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GitHub says internal repos exfiltrated after poisoned VS Code extension attack · Baitaphish