Microsoft's GitHub has confirmed a cyberattack involving unauthorised access to some of its internal repositories after a threat actor claimed it had stolen and was attempting to sell company data online.
In a series of posts, GitHub said it had “detected and contained a compromise of an employee device involving a poisoned VS Code extension,” on Tuesday.