TeamPCP exfiltrated 3,800 internal GitHub repositories after poisoning a VS Code extension. No customer data was affected, the company says.
TeamPCP gained access to GitHub's private source code after an employee unknowingly installed a malicious coding tool.
Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and ...