GitHub internal repositories breached
ID: a5bf2ae4-e938-5e38-99f8-b34109c77aa0
STIX ID: report--a5bf2ae4-e938-5e38-99f8-b34109c77aa0
Feed Name: Sophos Blogs
Threat Score
Sophos describes a supply-chain attack by TeamPCP (UNC6780) in which a poisoned VS Code extension (Nx Console) was used to harvest developer credentials and clone ~3,800 internal GitHub repositories; Sophos recovered a Python backdoor (cat.py) that polls the GitHub Search API for commands, provides IOCs and MITRE mappings, and issues hunting and remediation guidance including token rotation, extension removal, and artifact detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
