TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension

General News

Summary

TeamPCP (UNC6780) breached GitHub's internal codebase by delivering a poisoned Visual Studio Code extension that a GitHub employee installed. GitHub confirmed the compromise involved exfiltration of internal repositories, with the group's claim of roughly 3,800 repos directionally consistent with the investigation to date. GitHub removed the malicious extension, isolated the endpoint, prioritized rotation of high-impact secrets, and continues log analysis and monitoring as the response proceeds. TeamPCP has a history of supply-chain attacks against open-source tools, is attempting to sell or leak the stolen repositories, and the malicious VS Code extension was later identified as Nx Console.

Classifications

industries
No industries detected
applications
No applications detected

AskAI Classifications

Labels
No AI classifications detected

Linked Companies