GitHub hacked: 3,800 internal repositories breached – Claril Noticias

Microsoft-owned software hosting platform GitHub has confirmed a major security breach, revealing that cybercriminals successfully stole data from approximately 3,800 internal code repositories after compromising an employee’s device.

In a series of statements published on X, the development giant stated it has found no evidence suggesting that customer data stored outside these internal repositories has been affected. However, the company emphasised that its investigation remains active. The breach was detected and contained after security teams identified a compromised employee device, which had been infected via a malicious Visual Studio Code (VS Code) extension.

The rising threat of malicious developer extensions

Cybercriminals are increasingly targeting open-source projects and developer tools, such as coding extensions, to compromise programming environments. By exploiting widely used plugins, attackers can gain access to numerous downstream systems simultaneously, significantly amplifying the scale of their intrusion. GitHub has not publicly disclosed the name of the compromised VS Code extension involved in this incident.

TeamPCP claims responsibility for the intrusion

According to reports by The Record and Bleeping Computer, a cybercrime group operating under the name TeamPCP has claimed responsibility for the intrusion. The threat actors are reportedly offering the stolen repository data for sale on an underground hacking forum. GitHub has not yet commented on whether they have engaged in communication with the group or if a ransom demand has been made.

A history of high-profile cyberattacks

This is not the first high-profile target for TeamPCP. The group previously claimed responsibility for a data breach at the European Commission, which led to the theft of over 90 gigabytes of data from the organisation’s cloud storage. In that instance, the hackers obtained the EU executive arm’s cloud credentials by compromising Trivy, a popular vulnerability scanning tool, and distributing information-stealing malware to its downstream users.

This incident reflects a broader trend of supply-chain attacks targeting development infrastructure. Recently, OpenAI was affected by a similar campaign where malicious actors breached TanStack—a widely used web development platform—to distribute corrupted updates designed to harvest user credentials and security tokens.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *