A Poisoned VS Code Extension Just Gave Hackers Access to 3,800 GitHub Repos — In 18 Minutes
TeamPCP compromised the Nx Console VS Code extension (2.2M installs) for 18 minutes — but that was enough to breach 3,800 GitHub internal repos, Grafana Labs, and potentially OpenAI and Mistral AI.