Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

GitHub Confirms Breach — Thousands of Internal Repositories Hit After Employee Installs Malicious VS Code Extension

GitHub said the attack exposed about 3,800 internal repositories and prompted a rotation of compromised secrets after a poisoned extension spread through auto-updates.

  • On Wednesday, GitHub confirmed that a cyberattack compromised an employee's device, exposing internal repositories after the employee downloaded a poisoned version of the Console Microsoft Visual Studio Code extension.
  • Threat actors known as TeamPCP are selling an archive of roughly 4,000 repositories for $50,000, continuing their Shai-Hulud and Mini Shai-Hulud campaigns.
  • The malicious VSCode extension, which was live on Visual Studio Marketplace for only 18 minutes, allowed attackers to harvest sensitive data from AWS and Anthropic configurations.
  • Alexis Wales, Chief Information Security Officer of GitHub, stated, "We have no evidence of impact," regarding customer information stored outside GitHub-internal repositories, noting the company has rotated critical secrets.
  • This incident follows the TanStack supply chain attack, which impacted OpenAI, Mistral, and Grafana Labs; Jeff Cross, co-founder of Narwhal Technologies, noted the need for "fundamental changes in securing developer tooling.
Insights by Ground AI

20 Articles

On May 20, 2026, GitHub confirmed the compromise of internal deposits after an employee installed a malicious Microsoft Visual Studio Code extension. Nearly 3,800 internal deposits were exfiled by the TeamPCP group, which put the source code for sale for $50,000 on a cybercriminal forum. No impact [...] The post Anatomy of the attack Github, an extension VS Code malicious opens access to 3,800 deposits appeared first on IT SOCIAL.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news on Thursday, May 21, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal