trampolim.net
PT EN

Trampolim · Technology weekly

The Week in Tech

Issue 04Week of May 18–24, 202616 stories
Issue 04/May 18–24, 2026/Past issues/BusinessSecurityAIWorkHardwareTools

An editor extension yielded access to 3,800 internal repositories

The attack harvested cloud keys, package credentials and the file that says what the AI assistant can reach. The same month, sector figures showed spending above revenue.

From the studio

The developer's computer became the company's most concentrated asset

A criminal group compromised roughly 3,800 internal repositories through a trojanised code editor extension. What it took describes the problem well: cloud keys, package publishing credentials and configuration files from assisted coding tools.

That last item is the new one. An assistant's configuration file holds interface keys and the list of systems the assistant may reach, functioning as an access map already tested and working.

The attack's reach didn't come from the technique, it came from habit. Extensions install by individual decision, without review, and run with the developer's access, which usually includes credentials for several projects, with no short expiry.

The fix is familiar, cheap and unpopular because it annoys slightly every day: credentials that expire in hours, scope per project rather than per person, keys outside the repository, and review of what each installed tool can reach. None of that would have stopped the extension entering, and all of it would have reduced what it took.

In this issue

Sections

Book a call