GitHub says it is investigating an alleged compromise of its internal repositories after the threat actor group TeamPCP posted information claiming access to GitHub’s source code and internal organizations on a cybercrime forum. Multiple outlets report that TeamPCP claims to have accessed and exfiltrated thousands of repositories, with figures around 3,800 to about 4,000 repositories mentioned across coverage. GitHub states that its current assessment indicates the activity involved exfiltration of GitHub-internal repositories only. The company also says it has no evidence, at this stage, that customer information stored outside GitHub’s internal repositories—such as customer enterprises—was impacted.

Help Net Security and Infosecurity Magazine report that GitHub’s investigation points to a malicious or “poisoned” VS Code extension as the likely initial access vector. Dark Reading similarly frames the incident as a breach of internal repositories with TeamPCP taking credit for the theft. Overall, outlets agree GitHub is examining the scope of the claimed data exposure and the conditions that enabled the access, while assessing whether any external customer data was affected.