logo

GitHub internal repositories breached

ID: a5bf2ae4-e938-5e38-99f8-b34109c77aa0

STIX ID: report--a5bf2ae4-e938-5e38-99f8-b34109c77aa0

Feed Name: Sophos Blogs

Threat Score
88/100

Date Published: 2026-05-20

Date Updated: 2026-05-22

...
...

Sophos describes a supply-chain attack by TeamPCP (UNC6780) in which a poisoned VS Code extension (Nx Console) was used to harvest developer credentials and clone ~3,800 internal GitHub repositories; Sophos recovered a Python backdoor (cat.py) that polls the GitHub Search API for commands, provides IOCs and MITRE mappings, and issues hunting and remediation guidance including token rotation, extension removal, and artifact detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.