Threat Brief and Data Analysis: GitHub Internal Repository Compromise
ID: 030dc8b8-0e9b-5cd8-8199-9ecda57478e6
STIX ID: report--030dc8b8-0e9b-5cd8-8199-9ecda57478e6
Feed Name: BeGoodToAll
**Executive summary:** GitHub confirmed an internal repository compromise via a poisoned VS Code extension that resulted in exfiltration of roughly 3,874 internal repositories; the actor 'TeamPCP' is attempting to sell the dataset. The leaked list includes 343 high-priority repositories related to security, identity, CI/CD, and infrastructure, creating substantial supply-chain, secret-exposure, and operational risk; recommended actions include scoping the malicious extension, validating the repository inventory, rotating credentials, auditing CI/CD trust paths, and hunting for follow-on activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
