GitHub confirms theft of around 3,800 internal repositories
GitHub states that an employee was recently compromised through a malicious VSCode extension, leading to data theft. According to GitHub, the stolen data consists of roughly 3,800 GitHub-internal repositories.
The threat actor group TeamPCP has claimed responsibility and is currently auctioning the data on the darknet.
What this means for your business
That one of the world's largest platform providers was breached through an extension on a single developer machine says a great deal about where attacks actually arrive. It also says something about dependency: organisations building on GitHub inherit their supplier's incidents without being able to influence them. The point is not to change platform, but to know what sits with the supplier and how you find out when something goes wrong.
Berigo recommends
- Control which extensions are permitted in your code editors, and remove free installation rights from developer machines.
- Review which of your own secrets may sit in repositories hosted by a cloud provider, and move them out.
- Require security incident notification obligations in contracts with platform providers.
- Decide what your organisation would actually do if your source code were exposed, and write it down beforehand.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch