GitHub says hackers stole data from thousands of internal repositories

GitHub says hackers stole data from thousands of internal repositories

GitHub, the widely-used platform for developers and owned by Microsoft, has confirmed a significant security breach that resulted in the theft of data from approximately 3,800 internal code repositories. In a series of updates posted on X, the company stated that there is currently no evidence suggesting that customer information stored outside of its internal systems has been compromised. However, GitHub emphasized that its investigation into the matter is still ongoing. The breach was linked to a compromised employee device, which was infected via a malicious extension for Visual Studio Code, a popular code editor among developers. This incident highlights the increasing trend of hackers targeting widely-used open-source projects, particularly coding extensions, to gain unauthorized access to developers' computers and their respective projects. By infiltrating popular platforms, attackers can potentially access a large number of systems simultaneously, amplifying the effects of their malicious activities. Although GitHub has not identified the specific extension that was compromised, reports from The Record and Bleeping Computer indicate that a hacking group known as TeamPCP has claimed responsibility for the breach and is attempting to sell the stolen data on a cybercrime forum. GitHub has not yet responded to inquiries regarding whether the hackers have made any demands for ransom or communicated further about the breach. This is not the first time TeamPCP has been in the spotlight; they previously claimed a data breach that impacted the European Commission, resulting in the theft of over 90 gigabytes of sensitive data from the EU’s cloud storage. The hackers had initially compromised the European Commission’s cloud key during a prior breach at Trivy, a vulnerability scanning tool, by deploying malware to Trivy’s downstream users. Additionally, OpenAI faced a similar attack recently, where hackers infiltrated Tanstack, a platform utilized by web developers, to distribute updates containing malware aimed at stealing user passwords and tokens.

Sources : TechCrunch

Published On : May 20, 2026, 13:35

Cybersecurity
Experts Warn of Cyber Threats from Over-the-Air Updates in Vehicles

The rising adoption of over-the-air (OTA) technology in the automotive industry is raising alarms about potential cyber ...

CNBC | Jul 18, 2026, 23:15
Experts Warn of Cyber Threats from Over-the-Air Updates in Vehicles
AI
Moonshot AI's Kimi K3 Surges in Popularity, New User Sign-ups Temporarily Halted

Moonshot AI, a prominent player in China's AI landscape, is currently grappling with an overwhelming surge in demand for...

Business Insider | Jul 20, 2026, 04:15
Moonshot AI's Kimi K3 Surges in Popularity, New User Sign-ups Temporarily Halted
Startups
The Evolution of Team Dynamics in the Age of AI

Silicon Valley is experiencing a significant transformation in team structures as the influence of artificial intelligen...

Business Insider | Jul 19, 2026, 10:05
The Evolution of Team Dynamics in the Age of AI
AI
Christopher Nolan Warns: AI Might Be a Modern Trojan Horse

Renowned filmmaker Christopher Nolan, known for his latest adaptation of "The Odyssey," has expressed a cautious view to...

TechCrunch | Jul 19, 2026, 15:15
Christopher Nolan Warns: AI Might Be a Modern Trojan Horse
AI
AI Takes on the Soccer Stakes: Who Will Win the Betting Game?

How do you evaluate the predictive prowess of artificial intelligence? Recently, the CTO of the startup Obside shared a ...

Business Insider | Jul 19, 2026, 10:15
AI Takes on the Soccer Stakes: Who Will Win the Betting Game?
View All News