Categories: Cyber Security News

GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device

GitHub has confirmed unauthorized access to its internal repositories after detecting a compromised employee device infected through a malicious Visual Studio Code extension, the company disclosed in a series of official statements on May 20, 2026.

The Microsoft-owned code hosting platform said it identified and contained the breach after a poisoned VS Code extension was used to compromise an employee’s endpoint.

https://twitter.com/github/status/2056949168208552080?ref_src=twsrc%5Etfw

GitHub immediately removed the malicious extension version, isolated the affected device, and activated its incident response procedures.

GitHub’s investigation indicates the attacker successfully exfiltrated data from GitHub-internal repositories only, with no confirmed impact on public or customer-hosted repositories at this stage.

The company stated that a threat actor’s claims of accessing approximately 3,800 repositories are “directionally consistent” with their findings so far.

https://twitter.com/github/status/2056949169701720157?ref_src=twsrc%5Etfw

A notorious threat actor operating under the alias TeamPCP has claimed responsibility for the breach, alleging the exfiltration of proprietary organization data and source code.

The group is reportedly offering the stolen dataset for sale on underground cybercrime forums, demanding offers exceeding $50,000. Their own claims cite roughly 4,000 private repositories tied directly to GitHub’s main platform.

GitHub moved quickly to reduce further exposure following initial detection. Key containment actions included:

  • Rotating critical secrets and credentials overnight, prioritizing highest-impact credentials first
  • Isolating the compromised employee endpoint
  • Removing the malicious VS Code extension version from circulation
  • Initiating continuous log analysis to detect any follow-on attacker activity

The use of a malicious VS Code extension as an initial access vector highlights a growing threat in developer-targeted supply chain attacks.

Threat actors increasingly target developer tooling, IDE extensions, CI/CD plugins, and package managers to gain footholds inside high-value technology organizations.

A trusted extension turning malicious can bypass traditional security controls and exfiltrate sensitive credentials or tokens silently in the background.

GitHub confirmed it continues to analyze logs, validate secret rotation completeness, and monitor for secondary activity.

https://twitter.com/github/status/2056949172503453774?ref_src=twsrc%5Etfw

The company stated it will take additional remediation actions as warranted by the investigation and has committed to publishing a fuller incident report once the review is complete.

GitHub has not confirmed any customer data exposure at this time.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

The post GitHub Hacked – Internal Source Code Repositories Compromised via Employee Device appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

The New 2026 Apple iPad Air with M4 Chip Drops to a New All-Time Low Price for Memorial Day

Earlier this year, Apple released its 8th generation iPad Air tablet at a starting price…

2 minutes ago

McKeown Foundation to Host 35th Anniversary Gala on May 27 to Support Families Affected by Alzheimer’s Disease

According to the Alzheimer’s Association, nearly 7.4 million Americans suffer from the disease, with the…

3 minutes ago

InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection

A North Korea-linked hacker group has quietly upgraded one of its most dangerous tools, making…

4 minutes ago

Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions on Victim Hosts

A well-known advanced persistent threat group called Cloud Atlas has been caught using a dangerous…

4 minutes ago

Tekken Director Katsuhiro Harada Finally Takes a Trip to Waffle House

Tekken director Katsuhiro Harada finally found the time to take a trip to Waffle House.…

3 hours ago

Tekken Director Katsuhiro Harada Finally Takes a Trip to Waffle House

Tekken director Katsuhiro Harada finally found the time to take a trip to Waffle House.…

3 hours ago

This website uses cookies.