logo

GitHub says hackers stole data from thousands of internal repositories

ID: 989937ee-1e7c-59cc-91ad-c0d5bf9f97a1

STIX ID: report--989937ee-1e7c-59cc-91ad-c0d5bf9f97a1

Feed Name: TechCrunch Security News

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Zack Whittaker

...
...

GitHub disclosed a breach in which a poisoned Visual Studio Code extension compromised an employee device and led to theft of data from roughly 3,800 internal code repositories; GitHub says there is no evidence of impact to customer data stored outside internal repositories. Reports indicate the hacking group TeamPCP has claimed responsibility and is selling the stolen data, and the incident is linked to a broader trend of attackers targeting developer tooling and open-source supply chains (examples include prior compromises involving Trivy, TanStack, and the European Commission).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.