GitHub compromised, allegedly by TeamPCP

By
Follow google news

Around 3800 internal repositories exfiltrated.

Microsoft-owned web-based code hosting and collaboration platform GitHub has confirmed that it has been compromised, following reports that the TeamPCP hacking group had successfully attacked it.

GitHub compromised, allegedly by TeamPCP

GitHub said one of its employees' devices was compromised with a "poisoned" Microsoft Visual Studio Code extension (VSX), leading to what the company confirmed as an exfiltration of around 3800 private code repositories.

Paul McCarty of OpenSourceMalware told iTnews the VSX in question was nrwl.angular-console, with over 2.2 million installations and was compromised on March 18 this year.  

Screenshots of a web page published on the internet shows the TeamPCP hacking group allegedly putting up the internal GitHub repositories for sale.

GitHub said the current exfiltration involves only its internal code repositories.

The code hosting platform is investigating the incident and intends to publish a full report.

iTnews asked GitHub for further details on the breach and was told there is no evidence of impact to customer information stored outside of its internal repositories, such as their customer’s own enterprises, organisations, and repositories.

"Some of GitHub’s internal repositories contain information from customers, for example, excerpts of support interactions," the GitHub spokesperson said.

"If any impact is discovered, we will notify customers via established incident response and notification channels.

"We are closely monitoring our infrastructure for follow-on activity."

TeamPCP is a threat actor known for a run of software supply chain attacks in early 2026, targeting developer tooling and open-source package ecosystems including npm and PyPI.

The group's campaigns hit a broad set of targets in quick succession: the artificial intelligence application programming interface proxy library LiteLLM, Checkmarx's GitHub Actions workflows and OpenVSX plugins, and the widely used security scanning tool Trivy.

Researchers also linked TeamPCP to CanisterWorm, an npm publisher compromise that backdoored 29 packages in under 60 seconds using a novel command-and-control (C2) technique that routed traffic through a decentralised Internet Computer Protocol canister rather than a conventional server, making it resistant to standard takedown methods.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

GitHub compromised, allegedly by TeamPCP

GitHub compromised, allegedly by TeamPCP

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Victorian bulk porting scammer gets over two years in prison

Victorian bulk porting scammer gets over two years in prison

Log In

  |  Forgot your password?