Security
A trojanised editor extension yielded access to 3,800 internal repositories
The attack harvested cloud credentials, package registry keys and AI tooling configuration files.
Trampolim · Technology weekly
The attack harvested cloud keys, package credentials and the file that says what the AI assistant can reach. The same month, sector figures showed spending above revenue.
Security
The attack harvested cloud credentials, package registry keys and AI tooling configuration files.
Business
Quarterly figures show about $25 billion in annualised revenue against $30 billion in spending.
From the studio
A criminal group compromised roughly 3,800 internal repositories through a trojanised code editor extension. What it took describes the problem well: cloud keys, package publishing credentials and configuration files from assisted coding tools.
That last item is the new one. An assistant's configuration file holds interface keys and the list of systems the assistant may reach, functioning as an access map already tested and working.
The attack's reach didn't come from the technique, it came from habit. Extensions install by individual decision, without review, and run with the developer's access, which usually includes credentials for several projects, with no short expiry.
The fix is familiar, cheap and unpopular because it annoys slightly every day: credentials that expire in hours, scope per project rather than per person, keys outside the repository, and review of what each installed tool can reach. None of that would have stopped the extension entering, and all of it would have reduced what it took.
In this issue
Business
The arrangements aim to create a new channel for selling AI inside large companies.
AI
The number comes from a test using actual repository problems rather than synthetic exercises.
Business
The figure surpasses its competitor and arrives alongside a move toward listing.
Regulation
The decision removes a legal obstacle from the path to a public offering.
Tools
Two cloud companies target the category the model makers got to first.
Security
The file holds interface keys and the list of what the assistant can reach.
Business
Agent use spends differently from conversation, and one bucket penalised the advanced case.
Work
The entry point of the attack is the same thing that makes development environments productive.
Business
Growing users increases losses while unit cost depends on power and memory.
AI
Testing on an existing codebase measures something different from solving isolated exercises.
Work
Selling access reaches those who already know how to build; large companies need someone to make it work.
Security
The number of repositories reached comes from missing expiry and missing scope.
Business
One filed confidentially; the other had a legal obstacle removed the same month.
Work
Self-installed extensions, credentials without expiry and assistant configuration form one problem.
Sections
This paper is written by the same team that builds and operates the systems discussed here. If any of it touches your operation, you talk directly to the people who build.
Book a call