GitHub Confirms 3,800 Internal Repos Compromised via Poisoned VS Code Extension on May 20

GateNews

According to GitHub's official statement on May 20, 2026, the company confirmed that hackers compromised an employee's device using a malicious VS Code extension, gaining unauthorized access to approximately 3,800 internal repositories. GitHub detected and contained the breach within hours, isolating the affected endpoint, removing the malicious extension, and rotating critical credentials immediately.

Threat group TeamPCP claimed responsibility on underground forums, alleging it obtained data from roughly 4,000 private repositories, including proprietary source code and internal files, for over $50,000. GitHub stated there is currently no evidence of impact to customer data, enterprise accounts, or user repositories.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments