GitHub confirmed in May 2026 that hackers breached its systems and stole data from approximately 3,800 internal code repositories. The Microsoft-owned developer platform said it has “no evidence of impact to customer information stored outside of GitHub’s internal repositories,” though it noted its investigation remains ongoing.
The breach originated from a compromised employee device. GitHub said it “detected and contained a compromise of an employee device involving a poisoned VS Code extension” — a malicious plugin for Visual Studio Code, a widely used code editor among software developers.
A hacking group called TeamPCP has claimed responsibility for the attack, according to reports from The Record and Bleeping Computer. The group is reportedly selling the stolen data on a cybercrime forum. GitHub did not confirm whether it has received any communication from the hackers, including any ransom demand.
TeamPCP has been linked to previous attacks. The group previously claimed credit for a breach at the European Commission that resulted in the theft of more than 90 gigabytes of data from the EU executive body’s cloud storage. In that incident, the hackers obtained the European Commission’s cloud key during an earlier breach of Trivy, a vulnerability scanning tool, by pushing info-stealing malware to Trivy’s downstream users.
OpenAI was also recently targeted in a separate but similar attack, in which hackers compromised Tanstack, a web developer platform, to distribute malware capable of stealing passwords and tokens from users.
The GitHub breach highlights a broader trend of attackers targeting widely used developer tools and open-source projects. By compromising popular extensions or platforms, hackers can potentially reach large numbers of developers’ machines simultaneously, amplifying the scale of their attacks. GitHub did not name the specific VS Code extension involved in the incident.
Source: TechCrunch