GitHub has confirmed that attackers gained unauthorized access to thousands of its internal code repositories after compromising a single employee device via a malicious Visual Studio Code extension. The company said the incident, linked to the TeamPCP hacking group, resulted in the exfiltration of data from roughly 3,800 internal repositories but stressed that current evidence points to the breach being limited to GitHub’s own internal codebase.
According to GitHub’s initial findings, the attack began when the employee installed a poisoned VS Code extension that had been distributed through the official marketplace, a channel widely trusted by developers. Once the device was compromised, the attackers were able to use it as a foothold to access and extract data from GitHub’s internal repositories. GitHub has described the attackers’ claims of accessing around 3,800 repositories as “directionally consistent” with the results of its investigation so far.
The company has said there is currently no indication that customer repositories, enterprise environments, or projects hosted by external users were accessed as part of the intrusion. Public statements from GitHub emphasize that, based on the investigation to date, the breach appears restricted to internal repositories and systems, with no evidence so far of broad exposure of user-owned code or data.
GitHub has responded by revoking access tied to the compromised device, removing the malicious extension, and rotating credentials and other sensitive secrets that may have been exposed within the affected internal repositories. The company is continuing its forensic analysis and monitoring for any follow-on activity and has said it will notify customers if new evidence emerges that changes its current assessment of impact.
The incident comes weeks after researchers disclosed a separate critical remote code execution vulnerability in GitHub’s infrastructure, tracked as CVE-2026-3854, which has since been patched. While that flaw exposed millions of repositories in theory, GitHub and the researchers involved have said there is no evidence it was exploited in the wild, underscoring that the current breach is instead tied specifically to the poisoned VS Code extension and the compromised employee device.
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version,…
— GitHub (@github) May 20, 2026
Read Article: RBI Launches $5 Billion Dollar-Rupee Swap to Ease Liquidity Pressure

