logo

GitHub confirms breach of 3,800 repos via malicious VSCode extension

ID: 90a6c12a-0d37-5e04-a587-115c1c931d22

STIX ID: report--90a6c12a-0d37-5e04-a587-115c1c931d22

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Sergiu Gatlan

...
...

GitHub detected and contained a compromise of an employee device caused by a malicious (trojanized) VS Code extension that exfiltrated approximately 3,800 internal repositories; GitHub removed the extension, isolated the endpoint, and is investigating while the TeamPCP group publicly claimed the theft and attempted to sell the data. The report places this incident in the context of prior malicious VS Code extensions and supply-chain attacks targeting developer platforms, noting GitHub's widespread use and potential impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.