GitHub internal repositories breached
ID: a347a7fb-74de-5daa-864d-0b618d0efb29
STIX ID: report--a347a7fb-74de-5daa-864d-0b618d0efb29
Feed Name: Sophos Blogs
Sophos reports on a supply-chain compromise attributed to TeamPCP (UNC6780) where a malicious VS Code extension (Nx Console v18.95.0) installed on a GitHub employee's device was used to harvest developer credentials and clone approximately 3,800 internal repositories; the actor listed the stolen data for sale. Sophos recovered a Python backdoor (cat.py) that polls the GitHub Search API for commands and downloads signed Python payloads; the report provides IOCs (file hashes), MITRE-mapped TTPs, detection/hunt guidance, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
