Skip to content

GitHub confirms breach of 3,800 repos via malicious VSCode extension

9.5 relevance
Score Breakdown
technical depth
8
novelty
8
actionability
9
community
9
strategic
8
personal
10

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

GitHub breach via VSCode extension is a critical supply chain security incident for all developers.

Security bleepingcomputer.com
GitHub confirms breach of 3,800 repos via malicious VSCode extension
Summary

GitHub confirmed that roughly 3,800 internal repositories were breached after an employee installed a malicious VS Code extension, which was subsequently removed from the marketplace. The TeamPCP hacker group—previously linked to supply chain attacks on PyPI, NPM, and Docker—claimed responsibility and is demanding $50,000 for the stolen code. GitHub reports no customer data was affected, but this incident underscores the risk of supply chain attacks via developer tooling.

Author

Sergiu Gatlan

More from Sergiu Gatlan →