logo

GitHub says internal repos exfiltrated after poisoned VS Code extension attack

ID: 3b2247de-0ee2-559b-9e88-96228251c363

STIX ID: report--3b2247de-0ee2-559b-9e88-96228251c363

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

...
...

GitHub reported a compromise caused by a poisoned Visual Studio Code extension that led to exfiltration of internal repositories (claimed ~3,800). The incident, potentially tied to TeamPCP and Shai-Hulud-related activity, prompted GitHub to analyze logs, rotate secrets, and monitor for follow-on activity; the main concerns are leakage of internal source code, embedded secrets, and broader supply-chain risks to developer tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.