GitHub confirms that an intrusion involving 3,800 internal repositories was enabled after a GitHub employee installed a malicious Visual Studio Code (VS Code) extension. According to the reporting, the extension acted as the entry point for the TeamPCP hacking group. The attacker then gains access to GitHub’s private source code contained in those internal repositories. Both outlets describe the same basic sequence: the employee unknowingly installs the poisoned coding tool, which provides the attacker with a foothold, and the attacker subsequently reaches the company’s internal repositories. While specific technical details of how the repositories were accessed are not provided in the available reports, the confirmed scope of the incident is the number of affected internal repositories. The incidents described are characterized as unauthorized access facilitated through the compromised development environment rather than a direct breach of GitHub’s public services. The reports emphasize GitHub’s confirmation of the impact and the role of the malicious extension in enabling the access.