METABYTE
Back to articles

GitHub Breach via Malicious VSCode Extension Hits 3,800 Repos

Hackers used a rogue VSCode extension to steal tokens and compromise 3,800 GitHub repositories.

21 mai 20262 min read
GitHub Breach via Malicious VSCode Extension Hits 3,800 Repos

GitHub has confirmed a security breach where attackers compromised 3,800 repositories using a malicious Visual Studio Code extension. It's like inviting a pickpocket into your home because they wore a friendly face — except the pickpocket was a plugin you installed yourself.

How It Happened

The hackers published an extension on the VSCode marketplace that appeared harmless but secretly stole GitHub access tokens. The extension managed to harvest data from 3,800 repos before being taken down. The exact number of affected users hasn't been disclosed yet, but the scale is impressive.

Developers who installed this extension probably noticed something was off only when their CI/CD pipelines started acting like a cat on a hot tin roof — jumping and failing for no reason. Or when unfamiliar commits appeared in their repos. Sound familiar?

What to Do If You're Affected

GitHub has begun notifying owners of compromised repositories. If you receive such a notification, immediately:

  • Revoke any tokens that may have been stolen.
  • Check repo activity for suspicious commits.
  • Update passwords and enable two-factor authentication.
  • And of course, remove that extension.

This incident is a reminder that even the official extension marketplace isn't a guarantee of safety. Every plugin is a potential backdoor, especially if it requests access to your tokens.

METABYTE studio's take: We've always said trusting extensions blindly is like leaving your keys under the doormat. Use only verified tools and audit your repos regularly. And if you need help with security — we know how to keep your code safe from such surprises.

NEXT STEP

Liked the approach?

We apply the same principles to client projects: AI, automation, products that don't die after launch.