logo

TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension

ID: bd3eaf7d-82ee-511e-b1d0-bd417e8ebc08

STIX ID: report--bd3eaf7d-82ee-511e-b1d0-bd417e8ebc08

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Zeljka Zorz

...
...

Following claims by TeamPCP (UNC6780) that they breached GitHub’s private repositories, GitHub confirmed exfiltration of internal repositories after a poisoned Visual Studio Code extension was installed; the company removed the malicious extension, isolated the endpoint, rotated critical secrets and is continuing its investigation. TeamPCP — known for supply-chain attacks and an automated worm called Mini Shai-Hulud that steals CI/CD credentials and propagates to publish infected packages — is reportedly attempting to sell or will leak the stolen repository data if no buyer appears.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.