INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GitHub Internal Repos Stolen in 4K Breach Incident

| 2026-05-20 20:51 HIGH LOW DATA BREACH
Executive Summary
AI-generated
On May 20, 2026, TeamPCP, a financially motivated threat actor targeting the open source ecosystem, published an advertisement on a Dark Web data breach forum claiming to sell internal source code and organization data stolen from GitHub. The attack involved exfiltration of approximately 4,000 private repositories, with thousands more potentially affected as per GitHub's partial confirmation. According to TeamPCP, this was not a ransomware operation but rather the threat actor selling the stolen data for an interested buyer; if no buyer is found, they would leak it for free. The attack worked by exploiting a poisoned VS Code extension, which GitHub detected and contained, removing the malicious version, isolating the endpoint, and initiating incident response measures. As of now, GitHub continues to analyze logs, validate secret rotation, and monitor for follow-on activity while taking additional action as warranted during their investigation into the breach.
Technical Mitigations AI-generated
• Patch the VS Code extension to prevent exploitation by TeamPCP. • Monitor for and validate secret rotation, especially with high-impact credentials prioritized first. • Isolate compromised endpoints immediately after detection of malicious activity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎2026/05/20
Threat actors leveraged compromised developer tooling and trusted release workflows to distribute malicious code, including the poisoned VS Code extension that reached a GitHub employee's machine.
infrastructure Vs Code
infrastructure Visual Studio Code
Tactical Metrics
Metrics
infrastructure
‎Vs Code
Affected Product
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Intelligence Sources
Dark Reading 2026-05-20