GitHub Confirms Breach: Thousands of Internal Repositories Hit After Employee Installed Malicious VS Code Extension


  • GitHub confirms employee’s compromised device led to exfiltration of internal repositories via poisoned VSCode extension
  • Threat actors TeamPCP are selling an archive of around 4,000 repositories on the dark web, asking for $50,000 with shared samples for proof.
  • The group is also behind recent npm supply chain attacks, highlighting its ongoing campaign against developer ecosystems.

GitHub, one of the world’s largest open source code repositories, has confirmed that it was the victim of a cyberattack that resulted in the theft of its sensitive data.

In a brief announcement on X, GitHub said that one of its employees’ device was compromised when he downloaded a poisoned VSCode extension.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top