GitHub confirms that a threat actor exfiltrates thousands of GitHub-internal code repositories after compromising an employee’s device through a poisoned Visual Studio Code extension. Multiple outlets report GitHub’s assessment that the stolen data involves approximately 3,800 internal repositories. The incident is described as a supply-chain-style attack, where a malicious extension installed on an employee workstation enables unauthorized access and cloning of private repositories.

Reports also connect the event to the TeamPCP actor, which has been mentioned in relation to other recent compromises of software and security-related organizations. According to GitHub’s statements cited by outlets, the company contains the incident by removing the malicious extension version, isolating the affected endpoint, and starting incident response immediately. GitHub also states it currently sees the activity as limited to GitHub-internal repositories.

On potential broader exposure, sources note GitHub reports no evidence of impact to customer information stored outside of GitHub’s internal repositories. The investigation is ongoing, and outlets report that GitHub has not publicly confirmed details such as whether it received a ransom demand or whether it directly contacted the attackers.