INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TeamPCP Steals 3,800 Repositories via VS Code Extension
| 2026-05-20 13:55 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
On May 19, 2026, hackers from the TeamPCP group bypassed GitHub's security to gain access to internal systems and steal proprietary source code. The attackers compromised a corporate device belonging to one of GitHub’s developers using an unnamed poisoned extension for Microsoft Visual Studio Code (VS Code), allowing them to exfiltrate around 3,800 internal code repositories. TeamPCP has claimed responsibility for the breach and is selling the stolen source code and internal organisation data on a cybercrime forum with an initial asking price of over $95,000. The attackers warned that if no buyer materializes, they will leak repository archive names and files publicly for free. GitHub isolated the infected device, wiped the malicious VS Code extension, rotated high-impact credentials and cryptographic keys to revoke access, and is still monitoring its infrastructure for follow-on activity.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ha•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
May 2026
Threat actors, identified as TeamPCP (UNC6780), used a compromised VS Code extension to access and steal 3,800 internal GitHub repositories.
Click on any entity below to view its context and source!
infrastructure
Vs Code
“A single VS Code extension on one employee’s machine was enough to get access to 3,800 internal GitHub repositories.
infrastructure
2.2 installs
The day before the GitHub breach was disclosed, a completely separate extension called Nx Console, with 2.2 million installs, was also briefly backdoored.
2026/05/20
Threat actors from TeamPCP used a poisoned VS Code extension to compromise a corporate device and steal 3,800 repositories via an advanced infostealer worm.
Click on any entity below to view its context and source!
infrastructure
Vs Code
GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension.
…ion suggests that the attackers compromised a corporate device belonging to one of
GitHub
‘s developers while the entry point was an unnamed poisoned extension for Microsoft Visual Studio Code (
VS Code
), a popular tool used for writing software.
…X on 20 May 2026 to lay out its incident response, confirming that it has isolated the infected device, wiped the malicious VS Code extension, and spent the night rotating high-impact credentials and cryptographic keys to revoke the threat actors’…
Charlie Eriksen
, Security Researcher at Aikido Security, commented on the technical exposure of VS Code extensions and a separate, largely unreported incident the day before:
“The thing people underestimate about VS Code extensions is that they…
infrastructure
Visual Studio Code
…ion suggests that the attackers compromised a corporate device belonging to one of
GitHub
‘s developers while the entry point was an unnamed poisoned extension for Microsoft Visual Studio Code (
VS Code
), a popular tool used for writing software.
Tactical Metrics
Metrics
infrastructure
Vs Code
Affected Product
Click for context!
GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension.
…ion suggests that the attackers compromised a corporate device belonging to one of
GitHub
‘s developers while the entry point was an unnamed poisoned extension for Microsoft Visual Studio Code (
VS Code
), a popular tool used for writing software.
…X on 20 May 2026 to lay out its incident response, confirming that it has isolated the infected device, wiped the malicious VS Code extension, and spent the night rotating high-impact credentials and cryptographic keys to revoke the threat actors’…
Charlie Eriksen
, Security Researcher at Aikido Security, commented on the technical exposure of VS Code extensions and a separate, largely unreported incident the day before:
“The thing people underestimate about VS Code extensions is that they…
“A single VS Code extension on one employee’s machine was enough to get access to 3,800 internal GitHub repositories.
Metrics
infrastructure
Visual Studio Code
Affected Product
…ion suggests that the attackers compromised a corporate device belonging to one of
GitHub
‘s developers while the entry point was an unnamed poisoned extension for Microsoft Visual Studio Code (
VS Code
), a popular tool used for writing software.
Metrics
infrastructure
2,200,000
Installs
The day before the GitHub breach was disclosed, a completely separate extension called Nx Console, with 2.2 million installs, was also briefly backdoored.
Intelligence Sources
HackRead
2026-05-20
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
14x
organisation
Identified Entity
GitHub
entity
3x
tactic
Cyber Operation Type
Data Breach
tactic
3x
timeline
Temporal Reference
20 May 2026
date
2x
infrastructure
Affected Product
Vs Code
software
2x
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
Contextual Telemetry
Context Block
5 METRICS
general metric
Repositories
3,800
repositories
attribution
Attributing Entity
Google Threat Intelligence
authority
malware
Malware Payload
Shai-Hulud
tool
infrastructure
Installs
2,200,000
installs
general metric
Minutes
11
minutes
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.