GitHub supply-chain attack via malicious VS Code extension compromises 3,800 repos
GitHub suffered a supply-chain attack in which a malicious VS Code extension called Nx Console compromised 3,800 internal code repositories, one of this period's largest developer supply-chain security incidents.
Verification note: Scope of impact is from a tech-news roundup; for the official investigation findings, check GitHub's own announcement.