logo

Inside the Breach: How TeamPCP Poisoned a VS Code Extension to Exfiltrate 3,800 GitHub Repositories

ID: 77e527b6-a60b-589f-87dd-ebec294de009

STIX ID: report--77e527b6-a60b-589f-87dd-ebec294de009

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ddos

...
...

TeamPCP, a threat syndicate, conducted a supply-chain compromise by distributing a malicious Visual Studio Code extension that harvested credentials and enabled exfiltration of approximately 3,800 internal GitHub repositories (including Copilot, Enterprise Server, red-team tooling, and XSS-hardening research). The group is attempting to sell the stolen proprietary source code rather than extorting GitHub, and GitHub has confirmed the breach, isolated affected endpoints, rotated credentials, and pledged a detailed transparency report while investigations continue to look for lingering lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.