logo

GitHub internal repositories breached

ID: a347a7fb-74de-5daa-864d-0b618d0efb29

STIX ID: report--a347a7fb-74de-5daa-864d-0b618d0efb29

Feed Name: Sophos Blogs

Threat Score
85/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

...
...

Sophos reports on a supply-chain compromise attributed to TeamPCP (UNC6780) where a malicious VS Code extension (Nx Console v18.95.0) installed on a GitHub employee's device was used to harvest developer credentials and clone approximately 3,800 internal repositories; the actor listed the stolen data for sale. Sophos recovered a Python backdoor (cat.py) that polls the GitHub Search API for commands and downloads signed Python payloads; the report provides IOCs (file hashes), MITRE-mapped TTPs, detection/hunt guidance, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.