GitHub confirms breach: Thousands of internal repositories affected after employee installs malicious VS Code extension



  • GitHub confirms that an employee’s compromised device caused internal repositories to be leaked via a poisoned VSCode extension
  • TeamPCP threat actors are selling an archive of approximately 4,000 repositories on the dark web, asking for $50,000 with shared samples as proof.
  • The group is also behind recent attacks on the npm supply chain, highlighting its ongoing campaign against developer ecosystems.

GitHub, one of the largest open source code repositories in the world, has confirmed that it was affected by a cyberattack in which its confidential data was stolen.

In a brief announcement on X, GitHub said that one of its employees had his device compromised when he downloaded a poisoned VSCode extension.

Leave a Comment

Your email address will not be published. Required fields are marked *