According to GitHub's official statement on May 20, 2026, the company confirmed that hackers compromised an employee's device using a malicious VS Code extension, gaining unauthorized access to approximately 3,800 internal repositories. GitHub detected and contained the breach within hours, isolating the affected endpoint, removing the malicious extension, and rotating critical credentials immediately.
Threat group TeamPCP claimed responsibility on underground forums, alleging it obtained data from roughly 4,000 private repositories, including proprietary source code and internal files, for over $50,000. GitHub stated there is currently no evidence of impact to customer data, enterprise accounts, or user repositories.