INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GitHub confirms breach of 3,800 repos via malicious VSCode
| 2026-05-20 08:14 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A malicious VS Code extension, allegedly created by WhiteCobra, was installed on GitHub's platform after flooding the marketplace with 24 crypto-stealing extensions. The extension, which had basic ransomware capabilities and was later removed from the market, breached approximately 3,800 internal repositories, exfiltrating data only. This incident is part of a larger pattern of malicious VS Code extensions being used to steal developer credentials and sensitive data, as seen in previous incidents involving millions of installs. The attack works by exploiting vulnerabilities in the extension's code, allowing attackers to gain access to GitHub's internal systems. As of now, GitHub has secured the compromised device and is conducting an incident response, but no evidence suggests that customer data stored outside the affected repositories was impacted.
Technical Mitigations AI-generated
• Remove or update the malicious VSCode extension from your system immediately.
• Monitor for and block any suspicious activity related to TeamPCP, including indicators of compromise such as unusual API calls or unauthorized access attempts on GitHub repositories.
• Regularly scan your systems for XMRig cryptominer infections.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
2026/05/20
Threat actors used a malicious VSCode extension to target GitHub, resulting in the breach of approximately 3,800 internal repositories.
Click on any entity below to view its context and source!
infrastructure
1.5 installs
More recently, in January, two malicious extensions advertised as AI-based coding assistants with 1.5 million installs
exfiltrated data from compromised developer systems to servers in China
.
infrastructure
Vs Code
Later in the year, a
malicious extension with basic ransomware capabilities
snuck onto the VS Code marketplace after a threat actor named WhiteCobra
flooded it with 24 crypto-stealing extensions
.
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
The company has since removed the unnamed trojanized extension from the VS Code marketplace and has secured the compromised device.
"Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.
VS Code extensions are plugins that can be installed from the VS Code Marketplace (the official store for add-ons for Microsoft's code editor) to add features or integrate tools into the editor.
This isn't the first time a trojanized VS Code extension has been spotted on the marketplace, as multiple other malicious extensions with millions of installs have been used to steal developer credentials and other sensitive data over the last seve…
infrastructure
9 installs
For instance, last year, VSCode extensions with 9 million installs
were pulled over security risks
, and 10 more, posing as legitimate development tools,
infected users with the XMRig cryptominer
.
victims
4 organizations
GitHub's cloud-based platform is now used by over 4 million organizations (including 90% of the Fortune 100) and more than 180 million developers who contribute to over 420 million code repositories.
Tactical Metrics
Metrics
infrastructure
1,500,000
Installs
Click for context!
More recently, in January, two malicious extensions advertised as AI-based coding assistants with 1.5 million installs
exfiltrated data from compromised developer systems to servers in China
.
Metrics
infrastructure
Vs Code
Affected Product
Later in the year, a
malicious extension with basic ransomware capabilities
snuck onto the VS Code marketplace after a threat actor named WhiteCobra
flooded it with 24 crypto-stealing extensions
.
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
The company has since removed the unnamed trojanized extension from the VS Code marketplace and has secured the compromised device.
"Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.
VS Code extensions are plugins that can be installed from the VS Code Marketplace (the official store for add-ons for Microsoft's code editor) to add features or integrate tools into the editor.
This isn't the first time a trojanized VS Code extension has been spotted on the marketplace, as multiple other malicious extensions with millions of installs have been used to steal developer credentials and other sensitive data over the last seve…
Metrics
infrastructure
9,000,000
Installs
For instance, last year, VSCode extensions with 9 million installs
were pulled over security risks
, and 10 more, posing as legitimate development tools,
infected users with the XMRig cryptominer
.
Metrics
victims
4,000,000
Organizations
GitHub's cloud-based platform is now used by over 4 million organizations (including 90% of the Fortune 100) and more than 180 million developers who contribute to over 420 million code repositories.
Intelligence Sources
BleepingComputer
2026-05-20
GitHub confirms breach of 3,800 repos via malicious VSCode extension
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:33
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
organisation
Identified Entity
GitHub
entity
3x
timeline
Temporal Reference
2026/05/19
date
2x
infrastructure
Installs
1,500,000
installs
2x
tactic
Cyber Operation Type
Exfiltration
tactic
Contextual Telemetry
Context Block
13 METRICS
source region
Origin Country
China
country
infrastructure
Affected Product
Vs Code
software
general metric
Stealing Extensions
24
stealing extensions
general metric
Internal Repositories
3,800
internal repositories
general metric
More
10
more
malware
Malware Payload
Shai-Hulud
tool
general metric
Buyer
1
buyer
victims
Organizations
4,000,000
organizations
general metric
%
90
%
general metric
Fortune
100
fortune
general metric
Developers
180,000,000
developers
general metric
Code Repositories
420,000,000
code repositories
general metric
Surfaces
6
surfaces
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.