logo

Threat Brief and Data Analysis: GitHub Internal Repository Compromise

ID: 030dc8b8-0e9b-5cd8-8199-9ecda57478e6

STIX ID: report--030dc8b8-0e9b-5cd8-8199-9ecda57478e6

Feed Name: BeGoodToAll

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: BeGoodToAll

...
...

**Executive summary:** GitHub confirmed an internal repository compromise via a poisoned VS Code extension that resulted in exfiltration of roughly 3,874 internal repositories; the actor 'TeamPCP' is attempting to sell the dataset. The leaked list includes 343 high-priority repositories related to security, identity, CI/CD, and infrastructure, creating substantial supply-chain, secret-exposure, and operational risk; recommended actions include scoping the malicious extension, validating the repository inventory, rotating credentials, auditing CI/CD trust paths, and hunting for follow-on activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.