A laptop showing a code editor extension update, illustrating a VS Code extension supply chain attack and credential theft
APIs

The Extension That Opened GitHub’s Back Door

Imagine handing a new hire a badge that lets them walk into any room in the building, then never checking what they do once they’re inside — because, after all, they came with a recommendation from someone you trust. That is roughly what happens every time a developer installs an editor extension and lets it auto-update. The badge is real. The trust is real. But nobody is watching what the badge-holder does after the door closes. In May 2026, that gap turned a single VS Code extension into the opening move of a breach that reportedly reached inside GitHub’s own infrastructure.