logo

GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device

ID: 18aec3c5-d4f4-5968-9102-77a8b8cd4d68

STIX ID: report--18aec3c5-d4f4-5968-9102-77a8b8cd4d68

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Guru Baran

...
...

GitHub confirmed unauthorized access to internal repositories after a poisoned Visual Studio Code extension compromised an employee device; the attacker exfiltrated data from internal/private repositories (GitHub estimates align with claims of ~3,800–4,000 repos) and a criminal group calling itself TeamPCP is offering the dataset for sale. GitHub removed the malicious extension, isolated the affected endpoint, rotated critical secrets, and is conducting continuous log analysis while investigating further exposure and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.