You may have heard that Github had an incident recently involving the TeamPCP Supply Chain Worm, in this case a poisoned Visual Studio Code Extension. I cannot stress this enough, this is not a 'GitHub only' risk, these worms propagate by stealing personal access tokens, ssh keys, api keys, and other forms of credentials to infect other downstream users/consumers.
Did you or your company also install/update the same Visual Studio Code Extension that GitHub did?
These worms are spreading fast, May 11th, we saw announcements from StepSecurity that 174 packages were compromised. On May 19th, another round added an additional 323 packages as compromised.
If you have not already:
* You should be taking actions to block auto-updates of packages with Cooldown timers to prevent a package refresh that pulls in a poisoned package. https://cooldowns.dev/
* You should be implementing governance controls over Visual Studio Code to inventory and allow/deny list extensions: https://code.visualstudio.com/docs/enterprise/policies
* Lastly, should be checking your incident response processes to be able to quickly respond quickly to revocation of Personal Access Tokens (PATs) and other dev credentials. https://github.blog/changelog/2025-04-29-credential-revocation-api-to-revoke-exposed-pats-is-now-generally-available/