GitHub confirms breach – thousands of internal repositories hit after employee installs malicious VS Code extension


  • GitHub confirms that an employee’s compromised device led to the exfiltration of internal repositories via a poisoned VSCode extension
  • Threat actors TeamPCP are selling an archive of around 4,000 repos on the dark web, asking $50,000 with samples shared for proof
  • The group is also behind the latest npm supply chain attacks, highlighting its ongoing campaign against developer ecosystems

GitHub, one of the largest open source code repositories in the world, has confirmed that it was hit by a cyber attack in which sensitive data was stolen.

In a brief announcement on X, GitHub said that one of its employees had their device compromised when they downloaded a poisoned VSCode extension.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top