logo

GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension

ID: a13a8f06-0789-502b-88ec-522c5de2df27

STIX ID: report--a13a8f06-0789-502b-88ec-522c5de2df27

Feed Name: Infosecurity Magazine (News)

Threat Score
82/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

...
...

GitHub confirmed a security incident on May 19 where a poisoned Visual Studio Code extension on an employee device allowed a third party (claimed by TeamPCP) to access approximately 3,800 internal repositories; GitHub removed the malicious extension, isolated the endpoint, and rotated high‑impact credentials while investigating. The report contextualizes the incident within TeamPCP's wider supply‑chain campaigns (compromises of Trivy, KICS, backdoored PyPI releases), their distribution of credential‑stealing malware, and reported ties to extortion and ransomware groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.