INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GitHub Internal Repos Stolen in 4K Breach Incident
| 2026-05-20 20:51 HIGH LOW DATA BREACH
Executive Summary
AI-generated
On May 20, 2026, TeamPCP, a financially motivated threat actor targeting the open source ecosystem, published an advertisement on a Dark Web data breach forum claiming to sell internal source code and organization data stolen from GitHub. The attack involved exfiltration of approximately 4,000 private repositories, with thousands more potentially affected as per GitHub's partial confirmation. According to TeamPCP, this was not a ransomware operation but rather the threat actor selling the stolen data for an interested buyer; if no buyer is found, they would leak it for free. The attack worked by exploiting a poisoned VS Code extension, which GitHub detected and contained, removing the malicious version, isolating the endpoint, and initiating incident response measures. As of now, GitHub continues to analyze logs, validate secret rotation, and monitor for follow-on activity while taking additional action as warranted during their investigation into the breach.
Technical Mitigations AI-generated
• Patch the VS Code extension to prevent exploitation by TeamPCP.
• Monitor for and validate secret rotation, especially with high-impact credentials prioritized first.
• Isolate compromised endpoints immediately after detection of malicious activity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
2026/05/20
Threat actors leveraged compromised developer tooling and trusted release workflows to distribute malicious code, including the poisoned VS Code extension that reached a GitHub employee's machine.
Click on any entity below to view its context and source!
infrastructure
Vs Code
According to the Microsoft-owned company, GitHub yesterday detected and contained the compromise of an employee device, which involved a poisoned VS Code extension.
The idea that TeamPCP would hit GitHub through a
poisoned version of a Visual Studio Code (VS Code) extension
(or perhaps a typosquatted application) is well within the threat actor's capabilities, as many of its recent campaigns have involved su…
It is notable that the Microsoft-owned GitHub was compromised through a VS Code extension a year after GitHub committed itself to open source software security and two years after Microsoft committed itself to improved security practices.
VS Code, a Microsoft format, isn't necessarily a Microsoft extension.
"
"A VS Code extension runs with the same privileges as the editor itself, and once installed it has access to everything the developer can reach," he says.
…leveraged compromised developer tooling and trusted release workflows to distribute malicious code, including the poisoned VS Code extension that reached a GitHub employee's machine."
Kayne McGladrey, senior member of the Institute of Electrical a…
infrastructure
Visual Studio Code
The idea that TeamPCP would hit GitHub through a
poisoned version of a Visual Studio Code (VS Code) extension
(or perhaps a typosquatted application) is well within the threat actor's capabilities, as many of its recent campaigns have involved su…
Tactical Metrics
Metrics
infrastructure
Vs Code
Affected Product
Click for context!
According to the Microsoft-owned company, GitHub yesterday detected and contained the compromise of an employee device, which involved a poisoned VS Code extension.
The idea that TeamPCP would hit GitHub through a
poisoned version of a Visual Studio Code (VS Code) extension
(or perhaps a typosquatted application) is well within the threat actor's capabilities, as many of its recent campaigns have involved su…
It is notable that the Microsoft-owned GitHub was compromised through a VS Code extension a year after GitHub committed itself to open source software security and two years after Microsoft committed itself to improved security practices.
VS Code, a Microsoft format, isn't necessarily a Microsoft extension.
"
"A VS Code extension runs with the same privileges as the editor itself, and once installed it has access to everything the developer can reach," he says.
…leveraged compromised developer tooling and trusted release workflows to distribute malicious code, including the poisoned VS Code extension that reached a GitHub employee's machine."
Kayne McGladrey, senior member of the Institute of Electrical a…
Metrics
infrastructure
Visual Studio Code
Affected Product
The idea that TeamPCP would hit GitHub through a
poisoned version of a Visual Studio Code (VS Code) extension
(or perhaps a typosquatted application) is well within the threat actor's capabilities, as many of its recent campaigns have involved su…
Intelligence Sources
Dark Reading
2026-05-20
GitHub Confirms Breach, 4K Internal Repos Stolen
Dark Reading
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:33
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
organisation
Identified Entity
GitHub
entity
3x
timeline
Temporal Reference
2026/05/19
date
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
infrastructure
Affected Product
Vs Code
software
Contextual Telemetry
Context Block
4 METRICS
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
malware
Malware Payload
Shai-Hulud
tool
general metric
Repos Stolen
4,000
repos stolen
general metric
Buyer
1
buyer
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.