logo

GitHub Confirms Cyberattack Targeting Thousands of Internal Repositories

ID: 58140ce7-26b3-5294-9e14-cbebce109350

STIX ID: report--58140ce7-26b3-5294-9e14-cbebce109350

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ashish Khaitan

...
...

GitHub confirmed unauthorized access to thousands of internal repositories after a TeamPCP-linked attacker compromised an employee workstation via a malicious VS Code extension; GitHub says there is no evidence customer repositories were affected and rotated credentials while investigating. The report profiles TeamPCP as a cloud-focused criminal operation that uses automated internet-wide scanning to exploit exposed Docker, Kubernetes, Ray, and Redis services to build distributed infrastructure for proxying, hosting C2, extortion, ransomware, and cryptomining.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.