Attackers accessed thousands of GitHub internal repositories by compromising an employee device through a malicious Visual Studio Code extension.