GitHub confirms breach — thousands of internal repositories hit after employee installs malicious VS Code…

https://cdn.mos.cms.futurecdn.net/2viAsX89eJReYQEQ3i3SwH-750-80.jpg
  • GitHub confirms an employee’s compromised device led to exfiltration of internal repositories via a poisoned VSCode extension
  • Threat actors TeamPCP are selling an archive of roughly 4,000 repos on the dark web, asking $50,000 with samples shared for proof
  • The group is also behind recent npm supply‑chain attacks, highlighting its ongoing campaign against developer ecosystems

GitHub, one of the biggest open source code repositories in the world, has confirmed being hit by a cyberattack which saw its sensitive data stolen.

In a short announcement on X, GitHub saidone of its employees had their device compromised when they downloaded a poisoned VSCode extension.

The company removed the malware, isolated the endpoint, and started an investigation, which determined the attacker exfiltrated some sensitive data.

TeamPCP takes the blame

“Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only,” Github noted. “The attacker’s current claims of ~3,800 repositories...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more