S

EPISODE · May 20, 2026 · 0 MIN

GitHub Confirms Hack Impacting 3,800 Internal Repositories

from Security Stuff · host Trace3

GitHub has confirmed that approximately 3,800 internal repositories were compromised in a supply chain attack after an employee installed a malicious Visual Studio Code extension. The breach, claimed by hacking group TeamPCP who's demanding at least $50,000 for the stolen data, highlights a critical blind spot in developer security—extensions can access all data on a developer's machine including credentials and SSH keys. This marks the latest in a series of 2026 supply chain attacks by TeamPCP targeting developer tooling at major companies including Trivy, Checkmarx, Bitwarden, and TanStack, with security experts warning that most organizations lack visibility into what extensions developers are running on their machines.

Episode metadata supplied by the publisher feed · Published May 20, 2026

Embed this episode

NOW PLAYING

GitHub Confirms Hack Impacting 3,800 Internal Repositories

0:00 0:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security Stuff?

This episode is 0 minutes long.

When was this Security Stuff episode published?

This episode was published on May 20, 2026.

Can I download this Security Stuff episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!