GitHub says internal repos exfiltrated after poisoned VS Code extension attack
2026-05-20T19:23:59Z•46b83938c51bcb1caab4f83df1838f7c4b3eeb20801bc9a57fa6cabab649eba7
code-signingcredentials-exposeddata-exfiltrationdrupalgithublinux-kernelmacos-malwarenginx-riftnpmpatch-managementransomwaresoftware-supply-chainsupply-chain-attackvs-code-extension
What happened
A string of high-impact security incidents and supply-chain attacks dominated the roundup: GitHub says internal repositories were exfiltrated after a poisoned VS Code extension, multiple npm/TanStack cache-poisoning and Shai-Hulud supply-chain compromises spread credential-stealing malware, and researchers flagged active exploitation of NGINX Rift and Linux kernel privilege-escalation flaws. Microsoft disrupted an illegal code‑signing operation used by ransomware gangs while other stories detail exposed secrets in open GitHub repos, a critically urgent Drupal core patch, macOS stealer/backdoor
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 46b83938c51bcb1caab4f83df1838f7c4b3eeb20801bc9a57fa6cabab649eba7
- Enrichment time
- 2026-05-20T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.