GitHub Confirms Internal Breach
The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.

The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.
May 20, 2026 | 3 min read

GitHub confirmed Tuesday night that an unknown attacker gained access to some internal company repositories via a compromised VS Code extension that was installed on an employee machine. The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.
The first indications of the intrusion emerged Tuesday when the threat group TeamPCP posted claims online that it had breached GitHub’s internal systems and stolen the company’s source code and was offering the data for sale. GitHub eventually posted a statement on X confirming the intrusion, saying that it was still analyzing the logs and other artifacts from the incident.
“Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately,” the GitHub statement says.
“Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far. We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first. We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.”
“Trust, not sophistication, is what makes attacks like Nx Console, Durable Task Python SDK, and the Mini Shai-Hulud campaign across the AntV ecosystem work."
GitHub did not specify which compromised VS Code extension was the culprit, but on Monday a backdoored version of the NX Console extension was available for a short time before the compromise was detected and the bad version was removed. That incident was the resulted of stolen credentials.
"One of our developers were compromised by a recent security incident which leaked their Github credentials. These credentials have been temporarily revoked," the maintainers of NX Console said in their advisory.
“The malicious version collected credentials silently from the moment a developer opened any workspace. The community, including Aikido Intel, caught it quickly, with the version pulled within 18 minutes on the VS Code Marketplace and 36 minutes on Open VSX,” Shaun Brown at Aikido Security said in a post.
This kind of intrusion, which is becoming more and more common every day sadly, doesn’t rely on any sort of creative attack technique but rather exploits the trust that users have in the apps and other tools they rely on every day to do their jobs.
“Trust, not sophistication, is what makes attacks like Nx Console, Durable Task Python SDK, and the Mini Shai-Hulud campaign across the AntV ecosystem work. These are not sketchy packages and extensions from unknown publishers. They are tools developers use without thinking twice, precisely because it has the install count, the verified publisher badge, and the marketplace legitimacy that signal safety,” Brown said.
GitHub, which is owned by Microsoft, is a load-bearing resource in the developer community and attacks targeting the platform can have long-range consequences. Supply chain attacks against individual GutHub users and developers are quite common, and TeamPCP in particular has been running roughshod over open source projects, developer platforms, and other high-value targets for several months. The group has hit a number of different projects as part of its spree, and the ripple effects from attacks on Checkmarx GitHub Actions, OpenVSX, and other projects are still being felt.
GitHub did not specify how many internal repositories were exfiltrated or what those repositories contained.
May 20, 2026 | 3 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.