logo

A malicious VS code extension just breached GitHub ‘s internal repositories

ID: de2cd917-9a3e-57cc-afe9-ce47ecff02fe

STIX ID: report--de2cd917-9a3e-57cc-afe9-ce47ecff02fe

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Pierluigi Paganini

...
...

A trojanized Visual Studio Code extension installed by a GitHub employee led to compromise of the endpoint and exfiltration of approximately 3,800 internal GitHub repositories; the group TeamPCP claimed responsibility and sought $50,000, while GitHub removed the extension, isolated the device, and initiated incident response but confirmed the data was already exfiltrated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.