GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device
ID: 18aec3c5-d4f4-5968-9102-77a8b8cd4d68
STIX ID: report--18aec3c5-d4f4-5968-9102-77a8b8cd4d68
Feed Name: cybersecurityNews.com
GitHub confirmed unauthorized access to internal repositories after a poisoned Visual Studio Code extension compromised an employee device; the attacker exfiltrated data from internal/private repositories (GitHub estimates align with claims of ~3,800–4,000 repos) and a criminal group calling itself TeamPCP is offering the dataset for sale. GitHub removed the malicious extension, isolated the affected endpoint, rotated critical secrets, and is conducting continuous log analysis while investigating further exposure and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
