GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension
ID: 5e850874-bf17-50e8-83eb-16a3c40d4ee1
STIX ID: report--5e850874-bf17-50e8-83eb-16a3c40d4ee1
Feed Name: HackRead
Threat Score
**GitHub confirmed a breach on 19 May 2026 after TeamPCP (UNC6780) used a poisoned Visual Studio Code extension to compromise a developer device and exfiltrate roughly 3,800 internal repositories; the group claims the data for sale and researchers link the campaign to a self-replicating infostealer worm that steals CI/CD credentials and propagates via developer tooling.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
