EPISODE · May 20, 2026 · 0 MIN
GitHub Confirms Hack Impacting 3,800 Internal Repositories
from Security Stuff · host Trace3
GitHub has confirmed that approximately 3,800 internal repositories were compromised in a supply chain attack after an employee installed a malicious Visual Studio Code extension. The breach, claimed by hacking group TeamPCP who's demanding at least $50,000 for the stolen data, highlights a critical blind spot in developer security—extensions can access all data on a developer's machine including credentials and SSH keys. This marks the latest in a series of 2026 supply chain attacks by TeamPCP targeting developer tooling at major companies including Trivy, Checkmarx, Bitwarden, and TanStack, with security experts warning that most organizations lack visibility into what extensions developers are running on their machines.
Embed this episode
NOW PLAYING
GitHub Confirms Hack Impacting 3,800 Internal Repositories
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.