TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension
Summary
TeamPCP (UNC6780) breached GitHub's internal codebase by delivering a poisoned Visual Studio Code extension that a GitHub employee installed. GitHub confirmed the compromise involved exfiltration of internal repositories, with the group's claim of roughly 3,800 repos directionally consistent with the investigation to date. GitHub removed the malicious extension, isolated the endpoint, prioritized rotation of high-impact secrets, and continues log analysis and monitoring as the response proceeds. TeamPCP has a history of supply-chain attacks against open-source tools, is attempting to sell or leak the stolen repositories, and the malicious VS Code extension was later identified as Nx Console.
Classifications
industries
No industries detected
applications
No applications detected
AskAI Classifications
Labels
No AI classifications detected