The information is spread out across various articles, but from what I gather, a supply chain attack compromised the VS Code extension nx-console, which was then used to compromise Github. This all happened within two days.

Info on the Github attack:

Info about the nx-console attack:

  • tal@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 hours ago

    roughly 3,800 internal repositories

    I suppose that part of the moral here is to compartmentalize information internal to a company. Like, if you’re not on the team working on X, then you probably shouldn’t have repository access to X.