GitHub Confirms Hack Impacting 3,800 Internal Repositories
Microsoft-owned code-hosting platform GitHub on Wednesday morning confirmed that approximately 3,800 internal repositories were impacted in a supply chain attack.
On Tuesday, the infamous hacking group TeamPCP, known for a series of recent supply chain attacks targeting the open source software community, claimed the hack of 4,000 GitHub internal repositories.
Boasting about the incident on an underground hacking forum, the threat actor claimed the theft of source code and internal orgs, offering the allegedly stolen information to any buyer willing to pay at least $50,000 for it.
GitHub launched an investigation into the matter shortly after and roughly five hours later confirmed the attackers’ claims.
“Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far,” GitHub said.
The code-sharing platform immediately rotated critical secrets, prioritizing highest-impact credentials first.
Advertisement. Scroll...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE