[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwGzVxVgezU54Ppsd_noA-zNzgq7AvyeoCqnK8o9dSMc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"cf7d0d23-822b-4dc5-836e-563d58233304","github-compromised-through-poisoned-vs-code-extension-supply-chain-attack","f2230bb7-16ed-4af1-9f0b-dae2da6380c8","GitHub Compromised Through Poisoned VS Code Extension Supply Chain Attack","GitHub experienced a supply chain attack when an employee's device was compromised through a malicious VS Code extension, demonstrating how trusted development tools can become attack vectors. This incident highlights the critical vulnerability in software supply chains, where attackers target widely-used development environments to gain unauthorized access to sensitive systems. The compromise of a GitHub employee device could potentially have far-reaching consequences given GitHub's role in hosting millions of code repositories. Organizations must recognize that even trusted software extensions and plugins can be weaponized by sophisticated attackers targeting the software development lifecycle.","**Immediate actions:**\n- Audit all installed VS Code extensions and remove any non-essential or suspicious plugins\n- Implement endpoint detection and response (EDR) solutions on all developer workstations\n- Review and restrict extension installation permissions for development tools\n\n**Long-term improvements:**\n- Establish a vetted catalog of approved extensions and plugins for development environments\n- Implement zero-trust architecture principles for developer access to production systems\n- Create isolated development environments with limited access to critical infrastructure\n\n**Detection measures:**\n- Deploy continuous monitoring for unusual network traffic from developer workstations\n- Implement behavioral analytics to detect anomalous activities on employee devices\n- Establish automated alerts for unauthorized software installations on corporate devices",[12,13,14,15,16],"CIS Control 2 (Inventory and Control of Software Assets)","CIS Control 7 (Email and Web Browser Protections)","NIST SP 800-161 (Supply Chain Risk Management)","NIST Cybersecurity Framework PR.DS-6","ISO 27001 A.12.6.1 (Management of technical vulnerabilities)","published","2026-05-22T05:41:39.737175+00:00","2026-05-22T05:41:38.317968+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002FDarkWebInformer\u002Fstatus\u002F2057018844309340668","github-confirms-they-were-compromised-after-an-employee-device-involving-a-poiso-559bcf","GitHub confirms they were compromised after an employee device involving a poisoned VS Code exten...",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[38],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"f43868fc-b542-403c-876e-3116d2277c18","2026-05-20","afternoon","ThreatNoir Afternoon Brief — May 20","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-05-20\u002Fthreatnoir-afternoon-brief-2026-05-20.mp3"]