GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension
GitHub is the newest target of a data breach in which hackers from the infamous TeamPCP hackersbypassed its security to gain access to internal systems and steal proprietary source code. This widely used software hosting platform detected the breach on Tuesday, 19 May 2026.
Initial investigation suggests that the attackers compromised a corporate device belonging to one of GitHub‘s developers while the entry point was an unnamed poisoned extension for Microsoft Visual Studio Code (VS Code), a popular tool used for writing software.
This device compromise allowed the attackers to exfiltrate around 3,800 internal code repositories. This is shocking because it means a massive chunk of GitHub’s private codebase is now in adversaries’ hands.
The platform publisheda technical update on X on 20 May 2026 to lay out its incident response, confirming that it has isolated the infected device, wiped the malicious VS Code extension,...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE