GitHub formally acknowledged on Wednesday that a staff device hack via a tainted version of the Nx Console Microsoft Visual Studio Code (VS Code) extension was the cause of the intrusion of its internal repositories.
The announcement coincides with the Nx team’s disclosure that the extension, nrwl.angular-console, was compromised following a recent TanStack supply chain attack on one of its developers’ PCs. OpenAI, Mistral AI, and Grafana Labs are further businesses that were affected by the TanStack hack.
According to a statement from GitHub’s Chief Information Security Officer, Alexis Wales, “we have no evidence of impact to customer information stored outside of GitHub’s internal repositories, such as our customers’ own enterprises, organizations, and repositories.”
Customer data, such as snippets of support conversations, can be found in some of GitHub’s internal repositories. Customers will be informed through established incident response and notification channels if any impact is found read more about GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
