logo

GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension

ID: 5e850874-bf17-50e8-83eb-16a3c40d4ee1

STIX ID: report--5e850874-bf17-50e8-83eb-16a3c40d4ee1

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Deeba Ahmed

...
...

**GitHub confirmed a breach on 19 May 2026 after TeamPCP (UNC6780) used a poisoned Visual Studio Code extension to compromise a developer device and exfiltrate roughly 3,800 internal repositories; the group claims the data for sale and researchers link the campaign to a self-replicating infostealer worm that steals CI/CD credentials and propagates via developer tooling.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.