GitHub confirms breach after employee installs malicious VS Code extension

techradar.com

GitHub confirmed a breach where a compromised employee device led to the exfiltration of internal repositories via a malicious VS Code extension. Threat actors, identified as TeamPCP, are reportedly selling an archive of approximately 4,000 repositories on the dark web for $50,000, sharing samples as proof. TeamPCP is also linked to recent npm supply-chain attacks, indicating an ongoing campaign targeting developer ecosystems.


With a significance score of 4.1, this news ranks in the top 4.2% of today's 29994 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: