A poisoned VS Code extension led to a GitHub breach, and Microsoft owns every link in the chain
…The credentials were exposed through the npm ecosystem, and that ecosystem sits under GitHub, in turn sitting under Microsoft. The poisoned extension went out through the Visual Studio Marketplace, which Microsoft owns…