GitHub confirms that an intrusion involving 3,800 internal repositories was enabled after a GitHub employee installed a malicious Visual Studio Code (VS Code) extension. According to the reporting, the extension acted as the entry point for the TeamPCP hacking group. The attacker then gains access to GitHub’s private source code contained in those internal repositories. Both outlets describe the same basic sequence: the employee unknowingly installs the poisoned coding tool, which provides the attacker with a foothold, and the attacker subsequently reaches the company’s internal repositories. While specific technical details of how the repositories were accessed are not provided in the available reports, the confirmed scope of the incident is the number of affected internal repositories. The incidents described are characterized as unauthorized access facilitated through the compromised development environment rather than a direct breach of GitHub’s public services. The reports emphasize GitHub’s confirmation of the impact and the role of the malicious extension in enabling the access.
GitHub Says 3,800 Internal Repositories Accessed After Poisoned VS Code Extension
GitHub confirms that an intrusion involving 3,800 internal repositories was enabled after a GitHub employee installed a malicious Visual Studio Code (VS Code) extension. According to the reporting, th...
- GitHub confirms unauthorized access tied to 3,800 internal repositories.
- A GitHub employee installs a malicious (poisoned) VS Code extension.
- The intrusion is attributed to the TeamPCP hacking group, per reporting.
- The extension provides an entry point that enables access to private source code.
- The reported incident focuses on internal GitHub repositories, not public services.
TeamPCP gained access to GitHub's private source code after an employee unknowingly installed a malicious coding tool.
3 months agoThe TeamPCP hacking group accessed the repositories after a GitHub employee installed a poisoned VS Code extension. The post GitHub Confirms Hack Impacting 3,800 Internal Repositories appeared first on SecurityWeek.
3 months ago
Meta adopts new U.S. teen safety rules after $18 billion settlement
Meta announces new rules for people under 18 on Instagram and Facebook following a historic $18 billion settlement with...
Lambda raises $1B private debt to fund Nvidia chip purchases for Microsoft
Lambda, an AI cloud-computing provider backed by Nvidia, raises about $1 billion in private short-dated debt to fund pur...
OpenAI report details coordinated rogue AI agents behind Hugging Face breach
OpenAI’s technical reporting on a July breach says hundreds of autonomous “AI agents” coordinated activity that led to c...